Junglewise Threat Intelligence

CVE-2026-88771: Citrix NetScaler ADC and Gateway improper input validation

CVE-2026-88771 · Severity: critical · Exploited in the wild · Published 2026-09-27

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway, Citrix NetScaler. Vendors: Citrix.

Executive brief

Citrix NetScaler ADC and NetScaler Gateway are network appliances that manage traffic and application access for enterprises. An improper input validation flaw allows unauthenticated attackers to execute arbitrary commands on affected systems, potentially compromising network infrastructure and sensitive data.

Technical details

The vulnerability is an improper input validation issue in Citrix NetScaler ADC and Gateway that permits unauthenticated remote code execution. An attacker can exploit this without authentication by sending specially crafted input to execute arbitrary commands on the appliance, gaining full system compromise.

Affected products

  • Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1.37.279 FIPS and NDcPP
  • Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23

Timeline

  • 2026-09-27: disclosed

References

Related threats