CVE-2026-88771
NetScaler unauthenticated command execution
Citrix says CVE-2026-88771 lets an unauthenticated attacker run commands on NetScaler ADC and Gateway in the default configuration. CVSS 4.0 score 9.5. CISA listed it on 27 September 2026. It is not the later SAML denial-of-service bug.
- CVSS
- 9.5
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- Class
- RCE
- Status
- Active Exploitation
- KEV
- Listed in CISA KEV
- 0-day
- Yes
- Vendor
- Citrix
- Products
- NetScaler ADC, NetScaler Gateway
- Affected
- ADC and Gateway before 14.1-73.37 and before 13.1-64.23; ADC FIPS before 14.1-73.37 FIPS; ADC FIPS and NDcPP before 13.1.37.279. Default configuration. No extra feature is required.
- Fixed
- 14.1-73.37 and later, 13.1-64.23 and later, 14.1-73.37 FIPS and later, and 13.1.37.279 and later for FIPS and NDcPP.
- CWE
- CWE-20
- Published
- 27 Sept 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-88771 is improper input validation in Citrix NetScaler ADC and NetScaler Gateway. Bulletin CTX697096 says an unauthenticated attacker can execute arbitrary commands. The precondition is the default configuration. No extra feature has to be enabled. The CVSS 4.0 score is 9.5. CWE-20.
Citrix says exploits of this CVE and of CVE-2026-88772 were observed on unmitigated appliances. CISA added both to the Known Exploited Vulnerabilities catalog on 27 September 2026 and called them zero-days. The fixes in that bulletin are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 for FIPS and NDcPP, plus later builds on those lines. A public repository from watchTowr was created the same day.
CVE-2026-88772 is a separate memory-overflow issue in the same bulletin, with its own DTLS precondition. CVE-2026-88779 is a later SAML denial-of-service issue and is not closed by these builds. This record does not reprint commands.