What is CVE-2026-88771?
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Timeline
- 2026-09-27Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-27Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-09-28First covered in a defend.network daily briefing
- 2026-09-30CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Citrix NetScaler Improper Input Validation Vulnerability
Affected product
Citrix NetScaler
Remediation Steps
- Apply Citrix security updates released on September 27, 2026
- Verify patch deployment in non-production environment first
- Monitor for post-exploitation indicators following patching
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of September 2026 (September 28 – October 4)
- Citrix NetScaler, Oracle, Cloudflare RCEs under active exploitation; WAF bypasses escalate risks (2026-09-28)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.