Skip to content
THREATWIRE

CVE

CriticalActive ExploitationKEV0-day

CVE-2026-88771

NetScaler unauthenticated command execution

Citrix says CVE-2026-88771 lets an unauthenticated attacker run commands on NetScaler ADC and Gateway in the default configuration. CVSS 4.0 score 9.5. CISA listed it on 27 September 2026. It is not the later SAML denial-of-service bug.

CVSS
9.5
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Class
RCE
Status
Active Exploitation
KEV
Listed in CISA KEV
0-day
Yes
Vendor
Citrix
Products
NetScaler ADC, NetScaler Gateway
Affected
ADC and Gateway before 14.1-73.37 and before 13.1-64.23; ADC FIPS before 14.1-73.37 FIPS; ADC FIPS and NDcPP before 13.1.37.279. Default configuration. No extra feature is required.
Fixed
14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, and 13.1.37.279 and later for FIPS and NDcPP.
Published
27 Sept 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-88771 is improper input validation in Citrix NetScaler ADC and NetScaler Gateway. Bulletin CTX697096 says an unauthenticated attacker can execute arbitrary commands. The precondition is the default configuration. No extra feature has to be enabled. The CVSS 4.0 score is 9.5. CWE-20.

Citrix says exploits of this CVE and of CVE-2026-88772 were observed on unmitigated appliances. CISA added both to the Known Exploited Vulnerabilities catalog on 27 September 2026 and called them zero-days. The fixes in that bulletin are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 for FIPS and NDcPP, plus later builds on those lines. A public repository from watchTowr was created the same day.

CVE-2026-88772 is a separate memory-overflow issue in the same bulletin, with its own DTLS precondition. CVE-2026-88779 is a later SAML denial-of-service issue and is not closed by these builds. This record does not reprint commands.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-88771