NetScaler SAML exploit exploited in the wild; open-source checker scans 8 CVEs and 93 attacker IPs

cyb3rops · x · 2026-10-03

Citrix's NetScaler bulletin CTX697096 covers 8 CVEs, with CVE-2026-88771 and CVE-2026-88772 actively exploited and listed in CISA's KEV catalog. Attackers are using a SAML exploit to drop persistence, crashing patched devices in the process.

Security researcher ThomasPoppelgaard released an open-source read-only checker (netscaler-ctx697096-checker, v1.10) that answers three questions per appliance:

The --ioc sweep covers every public IoC: webshells, implants, backdoor admins, persistence, config theft, log injection, and 93 attacker IPs, each tagged before/after the fix. SAML users are advised to contact Citrix for a workaround, and internet-facing appliances should be treated as breached.

Original post →

More from Safety

Safety channel →