CVE-2026-88771
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
- Published Sep 27, 2026
- CVSS 9.5 critical
- 1.1% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) Help Net Security ·
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline The Hacker News ·
- Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier SecurityWeek ·
- Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 – Update 1 Canadian Centre for Cyber Security ·
- Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response Dark Reading ·
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes The Hacker News ·
- Multiple vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771, CVE-2026-88772 and others) JPCERT/CC ·
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs The Hacker News ·
- Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks SecurityWeek ·
- Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) Help Net Security ·