← Back to CVE intelligence
CVE intelligence

CVE-2026-88771

Citrix NetScaler input-validation remote code execution

Published Sep 27, 2026Sources checked Sep 28, 2026
9.5CRITICALCVSS out of 10
What this means

Exploitation reported: act now

Citrix Security Bulletins, 2026-09-27: exploitation attempts have been reported. This is separate from CISA KEV membership.

Public exploit: Not collected. Upgrade to the fixed build for your branch: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP, or a later release listed by Citrix.

CISA KEVNot listedBased on the latest collected catalog
EPSSUnavailableNo current score collected
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-88771?

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.