NetScaler command execution is CVE-2026-88771
Citrix bulletin CTX697096 confirms unauthenticated command execution on NetScaler in the default configuration. CISA listed CVE-2026-88771 on 27 September 2026. A later alert with no CVE id is this bulletin, not a new unnumbered bug.
Published 5 Oct 2026
What happened
On 27 September 2026 Citrix published bulletin CTX697096 and CISA added CVE-2026-88771 to the Known Exploited Vulnerabilities catalog. The bulletin calls it improper input validation. An unauthenticated attacker can execute arbitrary commands. The CVSS 4.0 score is 9.5. CISA’s alert the same day calls CVE-2026-88771 and CVE-2026-88772 critical zero-days and says partner reporting confirmed exploitation.
Before that bulletin, public warnings described NetScaler remote code execution with no CVE numbers yet. Those warnings now point at this bulletin. ThreatWire does not open a separate record for an unnumbered pair.
Who is affected
Citrix says every customer-managed NetScaler ADC and NetScaler Gateway deployment is in scope for CVE-2026-88771, including the default configuration. No additional feature has to be turned on. Secure Private Access hybrid deployments that use those instances are called out in the same bulletin. Citrix-managed cloud services are updated by Cloud Software Group and are outside the customer-applied-build instructions.
The fixed builds named with this CVE are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 for FIPS and NDcPP, and later releases on those lines.
What is confirmed
Citrix wrote that exploits of CVE-2026-88771 and CVE-2026-88772 had been observed on unmitigated appliances. CISA listed CVE-2026-88771 on 27 September 2026 with a federal due date of 30 September 2026. Known ransomware use is unknown. The catalog’s required action includes the vendor instructions and forensic triage under BOD 26-04. A watchTowr repository for this CVE was created on 27 September 2026. The status is Active Exploitation, and it is a 0-day because use was reported before the fix existed.
What is not confirmed
CVE-2026-88772 is in the same bulletin and is also in the KEV catalog, but it is not this record. Its precondition is DTLS, which Citrix says is the default on a Gateway VPN virtual server. The other CVE ids in CTX697096, 88773 through 88778, are not given their own records here.
CVE-2026-88779 is a later SAML memory overflow. Citrix describes that one as denial of service, and the builds in CTX697096 do not close it. An alert that still says “no CVE and no patch” is stale for 88771. The SAML issue already has an id, a bulletin, and a different fix.
What to do
Customer-managed appliances should move to the fixed build for their branch. CISA’s alert says to check for compromise and preserve evidence before the update when compromise is suspected, because the update can remove what an investigation would need. There is no configuration workaround in the bulletin that replaces the upgrade.
Sources: Citrix bulletin CTX697096, the CISA alert of 27 September 2026, the CISA KEV entry for CVE-2026-88771, NVD, and the public repository linked from the record.