ET WEB_SERVER Citrix Netscaler Unauthenticated Command Injection via HTTP Header (CVE-2026-88771) M1

7.0.35.0SID: 2072291Rev: 1Enabled0 views
Sourceet/open
Fileemerging-web_server.rules
CreatedSeptember 29, 2026
UpdatedSeptember 29, 2026
Classificationweb-application-attack
alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER Citrix Netscaler Unauthenticated Command Injection via HTTP Header (CVE-2026-88771) M1"; flow:established,to_server; http.header; content:"missed too many heartbeats"; fast_pattern; pcre:"/pitboss.*?PPE.*?missed\x20too\x20many\x20heartbeats/i"; content:"NSPPE"; distance:0; pcre:"/^.*?(?:[\x3b\x24\x26\x60\x7c]|\x25(?:25)?(?:3[bB]|2[46]|60|7[cC])|\x5c[rn])/R"; reference:url,labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/; reference:cve,2026-88771; classtype:web-application-attack; sid:2072291; rev:1; metadata:affected_product Citrix, attack_target Server, tls_state TLSDecrypt, created_at 2026_09_29, cve CVE_2026_88771, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2026_09_29, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)

Metadata

affected productCitrix
attack targetServer
tls stateTLSDecrypt
created at2026_09_29
deploymentInternal
confidenceMedium
signature severityMajor
tagExploit
updated at2026_09_29
mitre tactic idTA0001
mitre tactic nameInitial_Access
mitre technique idT1190
mitre technique nameExploit_Public_Facing_Application

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!