Citrix NetScaler is the over-priveleged receptionist of enterprise networking: it load-balances, it offloads SSL, it checks credentials, and at the thousands of organizations running NetScaler Gateway it is quite literally the front door through which remote workers get to work. It is also, to veterans of the server room, a repeat offender. This past Saturday, the security firm watchTowr caught wind of rumors that a NetScaler remote code execution bug was being actively exploited, checked the rumors against the national and international authorities it works with, and told its clients and the public to take appliances offline because — its words — this was “going to be bad.” The one party notably not making announcements at that point was Citrix.

By Monday, watchTowr had published the autopsy. CVE-2026-88771 is a pre-authentication command injection in the default configuration — meaning the appliance can be talked into running commands before it has checked who you are, which is a bit like a bouncer taking orders from whoever shouts loudest across the street. It is one of eight vulnerabilities Citrix patched in a single bulletin, CTX697096, and Citrix’s own bulletin confirms that exploits of CVE-2026-88771 and a second bug, CVE-2026-88772, were observed against unmitigated deployments. Both carry a CVSS v4 score of 9.5 out of 10, according to one write-up of the disclosure, which is roughly where the numbers turn red and bold.

The fix is a version number — several, in fact. Citrix wants customers on NetScaler ADC and Gateway 14.1-73.37 or later, or 13.1-64.23 or later of 13.1; on 14.1-FIPS 14.1-73.37 FIPS or later; and on 13.1-FIPS and 13.1-NDcPP 13.1-37.279 or later. Anything below that is, for the moment, a conversation piece.

The usual suspect pleads not guilty

To find the bug, watchTowr ran what it calls its “what the hell has changed” process: take the vulnerable NetScaler 14.1 build 73.30 and the fixed build 73.37, and compare them. The researchers’ first suspect was nsppe, the packet-processing engine where, by their account, almost every NetScaler vulnerability of the past decade has lived. But NetScaIer — excuse me, Citrix — “clearly likes to play games with us,” and this time nsppe was innocent.

Instead, the diff flagged an unglamorous Perl script named ns_monuploadd_err.pl. Its day job is housekeeping. When one of NetScaler’s packet engines crashes, a watchdog process called pitboss writes a line to the logs — a genuine line reads “pitboss: NSPPE-00 (12345) unexpectedly died” — and the system leaves behind a core file named something like NSPPE-00-12345. The script’s job was to reconstruct that name from the logs so the right core file could be packaged up for diagnostics.

The old code reconstructed the name by outsourcing it to the shell. In Perl, backticks mean “run this as a command and hand me the output,” and the script stuffed them with a four-tool assembly line: grep found the pitboss failure lines, tail -1 kept the last one, sed stripped the parentheses and everything before NSPPE, and awk printed the first two fields joined by a hyphen. So “NSPPE-00 (12345) unexpectedly died” became NSPPE-00-12345. A second backticked construction then built a find command to search for core files by that name. Every log line the script touched was being piped through a command interpreter — an interpreter with strong opinions about punctuation.

Citrix’s bulletin says the same thing in more funereal language: “A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands.” watchTowr, more succinctly: “We would say the 80s called, but did they even have phones?” The security world knows this genus well — just days ago it surfaced in a drowsy Windows telemetry task that could be steered into running the wrong PowerShell. Knowing the genus, though, is not the same as finding a specimen in your remote-access gateway.

The fix is the repair you’d order if you could: the shell is gone. The patched script matches the crash lines with a Perl regular expression directly, reads each log line by line, runs find in its no-shell form with an argument list rather than an interpretable string, and — for a final flourish of distrust — accepts only filenames composed entirely of harmless characters: letters, digits, slashes, dashes, dots. A script that once treated log contents as instructions now treats them as evidence.

What still needles watchTowr is the sequencing. The firm says it moved quickly on Saturday to corroborate the rumors through the authorities it has historically worked with — pausing to thank “the lorries for which the patches and various pieces of information fell off” — then warned clients and the public, given that many organizations running NetScalers are critical infrastructure. It wanted to call the situation “unprecedented,” it wrote, but couldn’t get past the laughing in its head, since the world learning about Citrix NetScaler CVEs before Citrix wakes up is apparently a tradition now. It has graciously volunteered to serve as “an extension of your PSIRT function,” though it warns Citrix it may have to compete with the other vendors it works with for charity.

One coda deserves preserving. Somewhere in Citrix’s orbit, watchTowr likes to imagine, works its favorite software developer — the team has a picture — whom they call AGI, pronounced Ah-gee. Whether or not AGI wrote ns_monuploadd_err.pl, the script has now been taught, at 9.5-out-of-10 expense, that punctuation from strangers is not to be trusted.