ET WEB_SERVER Citrix Netscaler Unauthenticated Command Injection via HTTP Header (CVE-2026-88771) M2
Sourceet/open
Fileemerging-web_server.rules
CreatedSeptember 29, 2026
UpdatedSeptember 29, 2026
Classificationweb-application-attack
alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER Citrix Netscaler Unauthenticated Command Injection via HTTP Header (CVE-2026-88771) M2"; flow:established,to_server ; http.header; content:"unexpectedly died"; fast_pattern; pcre:"/pitboss.*?PPE.*?unexpectedly\x20died/i"; content:"NSPPE"; distance:0; pcre:"/^.*?(?:[\x3b\x24\x26\x60\x7c]|\x25(?:25)?(?:3[bB]|2[46]|60|7[cC])|\x5c[rn])/R" ; reference:url,labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/ ; reference:cve,2026-88771 ; classtype:web-application-attack; sid:2072292; rev:1; metadata:affected_product Citrix, attack_target Server, tls_state TLSDecrypt, created_at 2026_09_29, cve CVE_2026_88771, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2026_09_29, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
References
Metadata
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!