LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 27, 2026
CVSS 9.5 · Critical⚠ Actively exploited (CISA KEV)
9.5
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Sep 30, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities catalog on Sep 27, 2026, with a federal patch deadline of Sep 30, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771 is an improper input validation flaw in Citrix NetScaler ADC and NetScaler Gateway. Public reporting describes it as allowing an unauthenticated attacker to execute arbitrary commands on affected systems. Because these products often sit at the network edge as application delivery controllers and remote-access gateways, successful abuse can give an outsider a foothold on infrastructure that handles authentication, traffic steering, and access to internal applications.

IT and security teams should treat this as a high-priority edge appliance issue: confirm exposure, inventory instances, and follow the vendor advisory and CISA direction without waiting for secondary write-ups. Exact affected builds, fixed releases, and any CVSS or exploit details must be taken from the official Citrix advisory and CISA notes—not from secondary summaries.

How it works

The weakness is catalogued as CWE-119 (improper restriction of operations within the bounds of a memory buffer) and is described in plain terms as improper input validation. In this class of flaw, data supplied by a client is not checked tightly enough before it is processed by privileged appliance code. When validation fails, memory corruption or related control-flow problems can follow, which on network appliances frequently translates into the ability to run attacker-chosen commands with the privileges of the vulnerable service.

CISA’s summary states that an unauthenticated attacker could execute arbitrary commands. That means the attack path does not require a valid login on the ADC or Gateway. Beyond that high-level description, public detail in the provided record does not include request paths, payloads, or step-by-step mechanics. Defenders should assume remote, unauthenticated reachability to the management or data plane interfaces that process client input, and should not rely on invented exploit specifics. Confirm attack surface and any published indicators only against the vendor advisory.

Am I affected? How to find it in your systems

Citrix NetScaler ADC and NetScaler Gateway typically run as physical or virtual appliances in DMZs, as reverse proxies, load balancers, SSL VPN / remote-access gateways, or hybrid cloud edge devices. They are often internet-facing or reachable from partner networks.

How to remediate

Patch first. Apply the Citrix updates named for CVE-2026-88771 in the official vendor advisory, following Citrix’s install and reboot/HA upgrade order. CISA’s required action is to apply mitigations in accordance with vendor instructions, ensure compliance with BOD 26-04 (prioritizing security updates based on risk), and follow CISA’s forensics triage requirements where applicable. For cloud-hosted or managed offerings, follow the BOD 26-04 cloud guidance; if mitigations are unavailable, discontinue use of the product as directed.

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until the vendor fix is installed.

Known ransomware use is not documented in the provided facts; absence of documentation is not proof that opportunistic exploitation will not occur.

If your data may have been exposed

Actively exploited edge vulnerabilities are a common path into broader breaches: session tokens, directory credentials, and application data that traverse the gateway can be at risk if an attacker achieved command execution. If forensics or anomalous logs suggest compromise, follow your incident response plan, preserve volatile evidence from the appliance, and complete any CISA forensics triage steps that apply to your organization. As a simple personal check, individuals can run a free exposure scan of their work email addresses against known breach datasets to see whether those identities already appear in public dumps—organizational investigation of the NetScaler estate remains the primary control.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · NetScaler
WeaknessCWE-20
CVSS base score9.5 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedSep 27, 2026
Added to CISA KEVSep 27, 2026
Federal patch deadlineSep 30, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities