• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-88771: unauthenticated command execution in Citrix NetScaler

Citrix NetScaler ADC and NetScaler Gateway contain an input validation flaw that allows an unauthenticated attacker to run arbitrary commands remotely. Multiple ADC and Gateway release lines are affected: ADC 14.x, ADC 13.x, Gateway 14.x, and Gateway 13.x prior to the vendor fixes listed. Exploitation requires only network access to the affected service; no credentials or user interaction are required. Public exploit code is available and vendor patches have been released.

Published Updated Source: CVE Program, NVD, CISA KEV

CVSS 3.1
9.8CRITICAL
EPSS
0.01063
CWE
CWE-20
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Act immediately. The issue is critical (CVSS 9.8), public exploit code exists, and vendor updates are available for the affected releases.

What is CVE-2026-88771?

Citrix NetScaler ADC and NetScaler Gateway contain an input validation flaw that allows an unauthenticated attacker to run arbitrary commands remotely. Multiple ADC and Gateway release lines are affected: ADC 14.x, ADC 13.x, Gateway 14.x, and Gateway 13.x prior to the vendor fixes listed. Exploitation requires only network access to the affected service; no credentials or user interaction are required. Public exploit code is available and vendor patches have been released.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Citrix NetScaler are affected?

BRANCHAFFECTEDFIXED
ADC 14.xbefore 14.1-73.3714.1-73.37
ADC 13.xbefore 13.1-64.2313.1-64.23
ADC 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
ADC 13.xbefore 13.1.37.279 FIPS and NDcPP13.1.37.279 FIPS and NDcPP
Gateway 14.xbefore 14.1-73.3714.1-73.37
Gateway 13.xbefore 13.1-64.2313.1-64.23

Is CVE-2026-88771 being exploited?

CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog on 2026-09-27, indicating it has been observed in active exploitation. Public exploit code is also available. As of 2026-09-29 there are public reports of exploit code and a KEV listing.

How to fix CVE-2026-88771

  1. Upgrade affected appliances to the vendor fixed builds: 14.1-73.37 or 13.1-64.23 (including the listed FIPS/NDcPP fixed builds).
  2. If immediate patching is not possible, restrict network exposure of NetScaler ADC and Gateway from untrusted networks and block access to management interfaces.
  3. Monitor logs and command activity for signs of compromise and follow vendor guidance and CISA mitigation instructions.
  4. Verify integrity of devices after patching and follow incident response procedures if suspicious activity is found.

Frequently asked questions

Is CVE-2026-88771 being actively exploited?

Yes. CISA added this CVE to its KEV catalog on 2026-09-27, and public exploit code is available.

Which versions contain fixes?

Vendor fixed builds include 14.1-73.37 and 13.1-64.23, plus the listed FIPS/NDcPP fixed builds (14.1-73.37 FIPS and 13.1.37.279 FIPS and NDcPP).

What if I cannot apply the patch right away?

Limit exposure by blocking access from untrusted networks, disable or isolate affected services where feasible, increase monitoring, and follow vendor and CISA mitigation guidance until you can upgrade.

References