Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-28 · updated: 2026-09-28 · tags: [cve, citrix] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: false

CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that permits an unauthenticated attacker to execute arbitrary commands. NVD rates it 9.5 critical (CVSS 4.0). Citrix states it affects every NetScaler ADC and Gateway deployment, "including those using the default configuration", with no optional feature needing to be enabled, and confirmed active exploitation when it published security bulletin CTX697096. Affected builds are ADC before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS and 13.1.37.279 FIPS and NDcPP, and Gateway before 14.1-73.37 and 13.1-64.23. CISA added it to the Known Exploited Vulnerabilities catalogue on 27 September, citing reports and partner threat intelligence confirming global exploitation. It is one of eight vulnerabilities fixed by the bulletin.

Attribute Detail
CVE CVE-2026-88771
CVSS 9.5 (critical)
Vendor / product Citrix NetScaler ADC / Gateway
Reported 2026-09-28