<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2026-88771 on Martin's Blog</title><link>https://mac.sploit.dk/tags/cve-2026-88771/</link><description>Recent content in CVE-2026-88771 on Martin's Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 29 Sep 2026 08:00:00 +0200</lastBuildDate><atom:link href="https://mac.sploit.dk/tags/cve-2026-88771/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-88771: From a Failed NetScaler Login to a Shell</title><link>https://mac.sploit.dk/blog/cve-2026-88771-netscaler-login-log-command-injection/</link><pubDate>Tue, 29 Sep 2026 08:00:00 +0200</pubDate><guid>https://mac.sploit.dk/blog/cve-2026-88771-netscaler-login-log-command-injection/</guid><description>&lt;p&gt;CVE-2026-88771 is a critical, unauthenticated command-execution vulnerability&#10;in NetScaler ADC and NetScaler Gateway. Citrix says that every customer-managed&#10;deployment is exposed, including the default configuration, and that&#10;exploitation has been observed.&lt;/p&gt;&#10;&lt;p&gt;The public bulletin gives defenders the important part: upgrade now. It does&#10;not explain how hostile input becomes a command. Comparing NetScaler 14.1&#10;builds 73.30 and 73.37 fills in much of that gap.&lt;/p&gt;&#10;&lt;p&gt;On 73.30, an unauthenticated client can place shell syntax in the username of a&#10;failed management login. The appliance writes that username to&#10;&lt;code&gt;/var/log/ns.log&lt;/code&gt;. A later warm-restart diagnostic pass can mistake the record&#10;for an NSPPE crash event, derive a supposed core-file name from attacker text,&#10;and interpolate it into a Perl backtick command. The backticks invoke a shell,&#10;so a filename becomes code.&lt;/p&gt;&#10;&lt;p&gt;That source-to-shell path is real. A harmless file-writing canary demonstrated&#10;command execution in an isolated lab when the original script was explicitly&#10;invoked with &lt;code&gt;-WR&lt;/code&gt;. The same input remained inert on 73.37, where Citrix&#10;replaced the permissive parser and shell-based &lt;code&gt;find&lt;/code&gt; invocation.&lt;/p&gt;&#10;&lt;p&gt;There is one important boundary: the login request does not itself launch the&#10;diagnostic script. Three genuine packet-engine recovery tests did not produce&#10;an observed &lt;code&gt;-WR&lt;/code&gt; invocation. A parser-shaped username is therefore strong&#10;evidence of an exploitation attempt, but not by itself proof that commands&#10;ran.&lt;/p&gt;</description></item></channel></rss>