🔴 CVE-2026-88771

CVE-2026-88771 is a critical improper input validation vulnerability (CWE-20) in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated remote attacker to execute arbitrary commands on the affected appliance without any user interaction. With a CVSS v4.0 score of 9.5, the vulnerability has been confirmed as actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog. NetScaler ADC and Gateway are by design internet-facing load balancing and remote access appliances, making virtually all unpatched deployments directly exposed to this attack.

← Back to Overview
HIGH_RISK
Risk Level
9.5
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-27

Added to CISA KEV: 2026-09-27 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-27)

Summary

CVE-2026-88771 is a critical improper input validation vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, which carries a CVSS v4 score of 9.5 [1]. This vulnerability is significant because it enables an unauthenticated attacker to execute arbitrary commands on the affected system without requiring any special configuration or enabled features [1].

Exploitation

  • Active Exploitation: Threat actors are actively exploiting this vulnerability in the wild globally, and CISA has added it to its Known Exploited Vulnerabilities (KEV) Catalog [2].
  • Threat Actors: While specific names are emerging, reports confirm multiple threat actors are currently leveraging the vulnerability against unmitigated deployments [2].
  • Availability: Proof-of-concept or exploit tools are actively being utilized by malicious actors following the discovery of this zero-day vulnerability [2].
  • Prerequisites: The attack is remote, does not require authentication, and does not require any user interaction [1].

Affected Products & Patches

  • Affected Versions: All deployments of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected [1].
  • Patch Availability: Cloud Software Group has released security updates for NetScaler ADC and NetScaler Gateway, beginning with version 14.1-73.37 and later releases [3].
  • Mitigations: Users are strongly urged to install the provided security updates immediately as there are no known manual workarounds suggested; patching is the primary remediation [3].

Impact

  • Access/Capability: Successful exploitation grants an attacker the ability to perform remote code execution, allowing full control over the compromised NetScaler appliance [1].
  • Business Risk: For internet-facing deployments, this risk is extreme, as it exposes the enterprise network to unauthenticated remote access, potentially leading to total system compromise, data theft, and lateral movement within the environment [2].

Sources

  1. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days ...

    CVE-2026-88771 (CVSS v4 score: 9.5) - An improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. · CVE-2026- ... CVE-2026-88771 (CVSS v4 score: 9.5) - An improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects all N…

  2. Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC ...

    CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively…

  3. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for ...

    Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. Citrix NetScaler ADC and Citrix NetScaler…