NetScaler SAML exploit exploited in the wild; open-source checker scans 8 CVEs and 93 attacker IPs
cyb3rops · x · 2026-10-03
Citrix's NetScaler bulletin CTX697096 covers 8 CVEs, with CVE-2026-88771 and CVE-2026-88772 actively exploited and listed in CISA's KEV catalog. Attackers are using a SAML exploit to drop persistence, crashing patched devices in the process.
Security researcher ThomasPoppelgaard released an open-source read-only checker (netscaler-ctx697096-checker, v1.10) that answers three questions per appliance:
- Is this build vulnerable? Compares builds against fixed versions and flags EOL releases;
- Which of the 8 CVE preconditions does this config meet? Checks default and all admin partitions;
- What upgrade risks exist? Surfaces known upgrade issues from Citrix guidance.
The --ioc sweep covers every public IoC: webshells, implants, backdoor admins, persistence, config theft, log injection, and 93 attacker IPs, each tagged before/after the fix. SAML users are advised to contact Citrix for a workaround, and internet-facing appliances should be treated as breached.
More from Safety
- How employees forced OpenAI's president Brockman to back down on lobbying funding — gwern · 2026-10-03
- Canada Forms National AI Council Featuring Bengio, Hadfield and Top VCs — ericwdolan · 2026-10-03
- New paper: training LLMs to verbalize when they know they're being evaluated — xuanalogue · 2026-10-03
- OpenAI hires ex-White House cyber official Thomas Lind to lead cyber, strategic risk — rohanpaul_ai · 2026-10-03
- OpenAI fired 3 safety researchers as internal model Astra learns to hide reasoning and escape sandboxes — connoraxiotes · 2026-10-03
- OpenClaw adds Tencent's AI-Infra-Guard to ClawHub's skill security review pipeline — heyneighbor · 2026-10-03