CVE-2026-88771

CRITICAL

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Complexity
LOW
Privileges
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 9/27/2026Modified: 9/29/2026

Related Intelligence (15)

CRITICALZero Day

Suspected State Hackers Exploited Citrix NetScaler for Weeks. 50,000 Devices May Still Be Exposed.

Datawater reports: Two critical NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, were used against organizations worldwide before a patch existed. CISA’s deadline is today. Patching alone will not tell you whether you were already breached. Threat level: Critical What: Two unauthenticated remote-code-execution flaws in Citrix NetScaler ADC and NetScaler Gateway, both CVSS 9.5. Status: Explo

CVE-2026-88771CVE-2026-88772
DataBreaches.net
CRITICALZero Day

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) appeared first on Unit 42 .

CVE-2026-88771CVE-2026-88772
Unit 42 (Palo Alto)
CRITICALZero Day

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek .

CVE-2026-88771CVE-2026-88772
SecurityWeek
CRITICALZero Day

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42 .

CVE-2026-88771CVE-2026-88772
Unit 42 (Palo Alto)
MEDIUMVulnerability

Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs

[object Object]

CVE-2026-88771
r/netsec
CRITICALZero Day

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor

CVE-2026-88771CVE-2026-88772
Rapid7
CRITICALZero Day

NetScaler admins told to patch critical zero-days in ADC and Gateway now

Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirme

CVE-2026-88771CVE-2026-88772
CSO Online
CRITICALZero Day

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek .

CVE-2026-88771CVE-2026-88772
SecurityWeek
CRITICALVulnerability

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

CVE-2026-88771
The Hacker News
CRITICALVulnerability

AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772

[object Object]

CVE-2026-88771CVE-2026-88772
r/blueteamsec
MEDIUMVulnerability

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

[object Object]

CVE-2026-88771CVE-2026-88772
r/blueteamsec
CRITICALVulnerability

NVD CRITICAL: CVE-2026-88771 — Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc...

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771
NIST NVD
CRITICALZero Day

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. [...]

CVE-2026-88771CVE-2026-88772
BleepingComputer
CRITICALZero Day

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

<p>CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: <a href="https://www.cve.org/CVERecord?id=CVE-2026-88771">CVE-2026-88771</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88772">CVE-2026-88772</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88773">CVE-2026-88773</a>, <a href="https://www.cve.

CVE-2026-88771CVE-2026-88772
CISA Advisories
HIGHVulnerability

CISA KEV: Citrix NetScaler — Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771Citrix NetScaler
CISA KEV

References (2)