CVE-2026-88771 is a critical improper input validation vulnerability (CWE-20) in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated remote attacker to execute arbitrary commands on the affected appliance without any user interaction. With a CVSS v4.0 score of 9.5, the vulnerability has been confirmed as actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog. NetScaler ADC and Gateway are by design internet-facing load balancing and remote access appliances, making virtually all unpatched deployments directly exposed to this attack.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-27
Added to CISA KEV: 2026-09-27 0 DAY BETWEEN CVE AND KEV
CVE-2026-88771 is a critical improper input validation vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, which carries a CVSS v4 score of 9.5 [1]. This vulnerability is significant because it enables an unauthenticated attacker to execute arbitrary commands on the affected system without requiring any special configuration or enabled features [1].
CVE-2026-88771 (CVSS v4 score: 9.5) - An improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. · CVE-2026- ... CVE-2026-88771 (CVSS v4 score: 9.5) - An improper input validation flaw that lets an unauthenticated attacker run arbitrary commands. It affects all N…
CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively…
Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. Citrix NetScaler ADC and Citrix NetScaler…