CVE-2026-88771
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Coverage 2 sources
-
2026-09-27
CISA Cybersecurity Advisories
high
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two Citrix NetScaler vulnerabilities to its Known Exploited Vulnerabilities Catalog.
-
2026-09-27
CISA Cybersecurity Advisories
critical
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
Citrix NetScaler ADC and Gateway have eight new vulnerabilities, including two critical zero-days exploited in the wild.
-
2026-09-28
Help Net Security
critical
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix patched RCE vulns in NetScaler ADC and Gateway, two of which were exploited as zero-days.
Mentioned with
CVE-2026-88772 CVE-2026-88773 CVE-2026-88774 CVE-2026-88775 CVE-2026-88776 CVE-2026-88777 CVE-2026-88778
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88778 TCP Initial Sequence Number (ISN) prediction