Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw
Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.
- Vendor
- Citrix
- Product
- NetScaler ADC, NetScaler Gateway
- CVSS
- N/A
- EPSS (exploit probability)
- N/A
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway. An unauthenticated attacker can exploit it to execute arbitrary commands remotely.
The flaw was exploited in the wild before Citrix had assigned CVE IDs or released patches. CISA added it to the Known Exploited Vulnerabilities catalog on September 27, 2026, with a federal patching deadline of September 30, 2026. Citrix confirmed the CVE ID and released patches on September 28, 2026.
What to do: Apply the Citrix-supplied patches immediately. Check the Citrix security advisory for specific patched build versions. Before patching, review appliance logs for signs of prior compromise: unusual administrative sessions, unexpected configuration changes, and any web shell indicators. See the NVD record and CISA KEV catalog for further details.
