Skip to main content
← Back to Demos
Malware intermediate · 15 min

Web Shell / C2 Beacon After Citrix NetScaler CVE-2026-8452 Pre-Auth RCE (watchTowr PoC)

On August 14, 2026, security firm watchTowr Labs published a deep-dive analysis of CVE-2026-8452, a heap-based buffer overflow in Citrix NetScaler ADC and NetScaler Gateway that Citrix had disclosed on June 30 as a denial-of-service / suspicious-behavior flaw. watchTowr demonstrated unauthenticated remote code execution when the appliance is deployed as a SAML SP or IdP, and released a proof-of-concept that installs a web shell on the compromised appliance. JPCERT/CC (advisory JPCERT-AT-2026-0024, Aug 15) states no exploitation had been confirmed as of August 15 but warns that PoC-driven attacks are expected; Citrix's bulletin CTX696604 covers six CVEs including CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817 and CVE-2026-13474. This demo reproduces the Linux-side implant pattern such an exploit leaves behind on a compromised appliance: a payload script acting as a web-shell / C2 beacon that contacts a loopback endpoint as a stand-in for command-and-control traffic before opening the calculator as a benign proof of execution. MetaDefender Adaptive Sandbox executes the payload in isolation, observes the beaconing behavior and command line, and flags the implant before it ever phones home from production infrastructure.

Attack Technique

Web Shell / C2 beacon implant dropped after pre-auth RCE (Citrix NetScaler CVE-2026-8452 pattern, watchTowr PoC)

MITRE ATT&CK

T1505.003 ↗

Platforms

linuxwindows

File Types

.sh.cmd

MetaDefender Capabilities

MetaDefender Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---