Skip to content

CVE-2026-88771

Citrix NetScaler ADC and Gateway remote code execution lets unauthenticated attackers run arbitrary commands (CVE-2026-88771)

Critical 9.5 KEV Published

Citrix NetScaler ADC and Gateway have an improper input validation flaw allowing an unauthenticated attacker to execute arbitrary commands over the network. CISA KEV lists it as actively exploited. Apply fixed releases: ADC 14.1-73.37 or 13.1-64.23; Gateway 14.1-73.37 or 13.1-64.23.

What happened

Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by an improper input validation issue. The CVE record describes it as allowing an unauthenticated attacker to execute arbitrary commands. The CVSS 4.0 vector rates it critical with a base score of 9.5: it is reachable over the network with low attack complexity, though some attack requirements must be present, and it requires no privileges or user interaction. Successful exploitation can have high impact on the confidentiality, integrity and availability of the affected system and subsequent systems.

CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog on 27 September 2026. CISA's SSVC assessment marks exploitation as active and automatable, with total technical impact. CISA's KEV due date is 30 September 2026. Fixed versions are recorded in the CVE record.

Who is affected

Affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway. ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP are affected. Gateway versions before 14.1-73.37 and before 13.1-64.23 are affected. These appliances are commonly placed at the network edge for application delivery and secure remote access, so an affected build that is reachable from the internet is particularly urgent.

What to do now

  1. Inventory every Citrix NetScaler ADC and Gateway deployment and confirm the installed release.
  2. Patch internet-facing systems first. The fixed releases are ADC 14.1-73.37, ADC 13.1-64.23, ADC 14.1-73.37 FIPS, ADC 13.1.37.279 FIPS and NDcPP, Gateway 14.1-73.37, and Gateway 13.1-64.23.
  3. Follow CISA's KEV required action and the vendor instructions in Citrix support article CTX697096: apply mitigations in accordance with vendor instructions, follow CISA's BOD 26-04 guidance and forensics triage requirements, and evaluate each asset's internet exposure. CISA's due date is 30 September 2026.
  4. If patching must be delayed, restrict network access to affected appliances and monitor for unexpected command execution. If no mitigation is available, CISA's required action says to discontinue use of the product.

How to detect it

Start with an inventory of Citrix NetScaler ADC and Gateway appliances and identify any running an affected build, particularly any reachable from the internet. Since the vulnerability allows command execution, also review these appliances for unexpected administrative changes or processes. No vendor- or CISA-published indicators of compromise are listed in the referenced sources.

Beyond the patch

Because CISA KEV and SSVC indicate active exploitation and the flaw is reachable over the network without credentials, this should be treated as an exposure problem as well as a patch problem. Managed Detection & Response (MDR) can help detect and respond to exploitation attempts, and Virtual CISO Services can help ensure that internet-facing NetScaler ADC and Gateway deployments are identified and governed so the next advisory is less disruptive.

Affected and fixed versions

ProductAffectedFixed in
ADC– < 14.1-73.37
– < 13.1-64.23
– < 14.1-73.37 FIPS
– < 13.1.37.279 FIPS and NDcPP
14.1-73.37
13.1-64.23
14.1-73.37 FIPS
13.1.37.279 FIPS and NDcPP
Gateway– < 14.1-73.37
– < 13.1-64.23
14.1-73.37
13.1-64.23

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.