Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-88771

Citrix NetScaler ADC/Gateway Unauthenticated RCE via Input Validation Flaw

Citrix NetScaler ADC and Gateway improper input validation flaw allows unauthenticated remote code execution; actively exploited and CISA KEV listed.

cat cve-2026-88771.json
Vendor
Citrix
Product
NetScaler ADC, NetScaler Gateway
CVSS
N/A
EPSS (exploit probability)
N/A
Status
kev
CISA patch-by (BOD 22-01)
Published

CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway. An unauthenticated attacker can exploit it to execute arbitrary commands remotely.

The flaw was exploited in the wild before Citrix had assigned CVE IDs or released patches. CISA added it to the Known Exploited Vulnerabilities catalog on September 27, 2026, with a federal patching deadline of September 30, 2026. Citrix confirmed the CVE ID and released patches on September 28, 2026.

What to do: Apply the Citrix-supplied patches immediately. Check the Citrix security advisory for specific patched build versions. Before patching, review appliance logs for signs of prior compromise: unusual administrative sessions, unexpected configuration changes, and any web shell indicators. See the NVD record and CISA KEV catalog for further details.