Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
netscaler-ctx697096-checker — Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): verifies build, CVE preconditions and upgrade risks, and sweeps public IoCs for compromise. | Kitploit
Tools/GitHubGitHub/thomaspoppelgaard/netscaler-ctx697096-checker
Defensive ToolsIndicator of Compromise (IOC) ManagementReconnaissanceVulnerability ScannersVulnerability AnalysisConfiguration AuditingForensicsWeb SecurityNetwork Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Threat Intelligence
Incident Response
Log Analysis
GitHubthomaspoppelgaard/netscaler-ctx697096-checker

netscaler-ctx697096-checker

Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): verifies build, CVE preconditions and upgrade risks, and sweeps public IoCs for compromise.

View RepositoryWebsite
12251 day agoNot yet reviewed
Share

netscaler-ctx697096-checker

Read-only precondition and exposure checker for the Citrix NetScaler ADC / NetScaler Gateway security bulletin CTX697096, covering CVE-2026-88771 through CVE-2026-88778.

⚠️ CVE-2026-88771 and CVE-2026-88772 are exploited in the wild and are listed in the CISA KEV catalog. Upgrade now, and assume breach on internet-facing appliances.

🚨 New since 2 October: a SAML zero-day hits patched appliances too. Citrix confirms a new issue, separate from CTX697096: crafted SAML requests crash NetScalers on the fixed builds, and commands have been seen running on a patched appliance. You are affected if your config has add authentication samlAction or add authentication samlIdPProfile (Citrix guidance). Citrix released a new responder policy on 3 October: ask Citrix Support for it, and upgrade as soon as the new bulletin and builds are out. Checker v1.11 shows whether you are affected, whether a mitigation policy is bound and the Responder feature is on, and reports injection attempts since 2 October as "may have run".

It answers four questions for each NetScaler:

  1. Is this build vulnerable? It checks the build against the fixed versions and flags end-of-life releases.
  2. Which of the eight CVE preconditions does this configuration meet? It checks the default partition and every admin partition.
  3. What could go wrong during the upgrade? It flags known upgrade issues from the Citrix guidance.
  4. Was I hacked? With --ioc, it checks every public indicator of compromise for CVE-2026-88771 published so far, and tells you whether attack traffic came before or after your fix.

For background, a timeline and step-by-step remediation, see the accompanying blog post: CVE-2026-88771 through CVE-2026-88778 – what you should know and how to fix your NetScaler.

It is a single POSIX shell script with no dependencies. It runs on the appliance itself or against an exported ns.conf on any Linux, macOS or WSL machine.


Fix check and IoC sweep

Without switches, the script checks exposure and fix status. With --ioc, it also checks for compromise: every public indicator of compromise for CVE-2026-88771 and CVE-2026-88772 published so far, from Mandiant/GTIG, Unit 42, Arctic Wolf, watchTowr, CERT-EU, GreyNoise, Beazley Security, Elastic, PitScaler.com and its sources, and others (see the credits below).

Use it together with the official Citrix IoC scan, not instead of it.

  • The official IoCs are only available through NetScaler Console (Security Advisory, then Indicators of Compromise) or from Citrix Support. Run that scan first, before you upgrade or reboot, because some traces may only exist in memory.
  • This script only knows the indicators that have been published. A clean result means none of those were found in the files and logs that are still on the box. It does not prove the appliance was never compromised. Check the log-retention lines to see how far back that goes.
  • On an HA pair, run it on both nodes. HA file sync copies webshells to the peer.

What --ioc checks (appliance only)

Context: how much is a clean result worth?

  • When the fixed build started running. Taken from the kernel that installns copies to /flash (ns-<build>.gz) and the first boot after the install (/var/nsinstall/installns_state_post_reboot). Every attack line is tagged before or after this time, and the output says where the date comes from. On a vulnerable build it shows when the exposure started, or that a newer build is installed but not running yet. Override with --fixdate if needed.
  • Last boot. It shows whether in-memory traces can still be found, and warns if a vulnerable box rebooted recently.
  • Log retention for ns.log, notice.log and httpaccess-vpn.log. It warns when less than 7 days are kept, because log-based checks can't see further back.
Download Tool