
Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): verifies build, CVE preconditions and upgrade risks, and sweeps public IoCs for compromise.
Read-only precondition and exposure checker for the Citrix NetScaler ADC / NetScaler Gateway security bulletin CTX697096, covering CVE-2026-88771 through CVE-2026-88778.
⚠️ CVE-2026-88771 and CVE-2026-88772 are exploited in the wild and are listed in the CISA KEV catalog. Upgrade now, and assume breach on internet-facing appliances.
🚨 New since 2 October: a SAML zero-day hits patched appliances too. Citrix confirms a new issue, separate from CTX697096: crafted SAML requests crash NetScalers on the fixed builds, and commands have been seen running on a patched appliance. You are affected if your config has
add authentication samlActionoradd authentication samlIdPProfile(Citrix guidance). Citrix released a new responder policy on 3 October: ask Citrix Support for it, and upgrade as soon as the new bulletin and builds are out. Checker v1.11 shows whether you are affected, whether a mitigation policy is bound and the Responder feature is on, and reports injection attempts since 2 October as "may have run".
It answers four questions for each NetScaler:
--ioc, it checks every public indicator of compromise for CVE-2026-88771 published so far, and tells you whether attack traffic came before or after your fix.For background, a timeline and step-by-step remediation, see the accompanying blog post: CVE-2026-88771 through CVE-2026-88778 – what you should know and how to fix your NetScaler.
It is a single POSIX shell script with no dependencies. It runs on the appliance itself or against an exported ns.conf on any Linux, macOS or WSL machine.
Without switches, the script checks exposure and fix status. With --ioc, it also checks for compromise: every public indicator of compromise for CVE-2026-88771 and CVE-2026-88772 published so far, from Mandiant/GTIG, Unit 42, Arctic Wolf, watchTowr, CERT-EU, GreyNoise, Beazley Security, Elastic, PitScaler.com and its sources, and others (see the credits below).
Use it together with the official Citrix IoC scan, not instead of it.
- The official IoCs are only available through NetScaler Console (Security Advisory, then Indicators of Compromise) or from Citrix Support. Run that scan first, before you upgrade or reboot, because some traces may only exist in memory.
- This script only knows the indicators that have been published. A clean result means none of those were found in the files and logs that are still on the box. It does not prove the appliance was never compromised. Check the log-retention lines to see how far back that goes.
- On an HA pair, run it on both nodes. HA file sync copies webshells to the peer.
--ioc checks (appliance only)Context: how much is a clean result worth?
installns copies to /flash (ns-<build>.gz) and the first boot after the install (/var/nsinstall/installns_state_post_reboot). Every attack line is tagged before or after this time, and the output says where the date comes from. On a vulnerable build it shows when the exposure started, or that a newer build is installed but not running yet. Override with --fixdate if needed.ns.log, notice.log and httpaccess-vpn.log. It warns when less than 7 days are kept, because log-based checks can't see further back.