Citrix NetScaler Improper Input Validation Vulnerability
TL;DR 📌
- Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
- Highest CVSS: 9.5 (Critical).
- Listed in CISA KEV (2026-09-27) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-88771.
What it is
CVE-2026-88771 is an improper input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated attacker to execute arbitrary commands. The CVSS 4.0 vector confirms this is reachable over the network (AV:N) with low attack complexity (AC:L), requires no privileges (PR:N) and no user interaction (UI:N), though it does require some attack requirements to be met (AT:P). Impact is rated high across confidentiality, integrity and availability, both for the vulnerable system and subsequent systems, giving a base score of 9.5.
The advisory does not detail the specific endpoint or protocol involved, but the access path is clear: no authentication is needed, which typically points at a management or gateway-facing interface rather than something buried behind existing session state. Given the affected components are NetScaler ADC and NetScaler Gateway, this sits on infrastructure that is commonly exposed at the network edge for remote access and load balancing.
The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-09-27, meaning it is known to be exploited.
What to do
- Check which NetScaler builds you run against the versions listed in the advisory: ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway before 14.1-73.37 and before 13.1-64.23. Anything below these is vulnerable.
- Consult Citrix’s advisory directly for the specific fixed release numbers and download links, as fixed version numbers were not included in the data reviewed for this brief beyond the “before” boundaries above.
- Given KEV listing, treat this as an active patching priority rather than a routine maintenance item — apply fixes as soon as they can be validated in your environment.
- Review NetScaler management and gateway interfaces for exposure; where patching cannot happen immediately, restrict access to management planes from untrusted networks as an interim measure.
- After patching, review logs for signs of command execution attempts predating the fix, particularly around the KEV addition date of 2026-09-27.
For leadership 🧭
Executive summary. NetScaler ADC and Gateway appliances running versions below the fixed builds can be taken over remotely by an attacker with no credentials and no user interaction, and this is already listed by CISA as actively exploited. Given these devices typically sit at the network edge handling remote access and load balancing, this needs patching or interim access restriction this week, not at the next maintenance window.
Why it matters:
- NetScaler ADC and Gateway are commonly deployed at the perimeter for remote access and load balancing, so the vulnerable interface is often reachable directly from the internet.
- No authentication or user interaction is required, and CISA’s KEV listing confirms exploitation is already happening, removing any benefit of the doubt on urgency.
- Successful exploitation gives arbitrary command execution with high impact on confidentiality, integrity and availability of the device and downstream systems it fronts.
- Affected builds span both standard and FIPS/NDcPP editions of ADC and Gateway before 14.1-73.37 and 13.1-64.23, so version checks need to cover all deployed variants, not just the default build.
Now / Next / Later:
- Now: Identify every NetScaler ADC and Gateway instance in the estate and check its build number against the affected ranges (before 14.1-73.37, before 13.1-64.23, and the FIPS/NDcPP equivalents).
- Next: Apply Citrix’s fixed releases to all vulnerable instances in the next available change window, prioritising anything with management or gateway interfaces reachable from untrusted networks.
- Later: Establish a standing rule that internet-facing NetScaler management planes are never directly reachable from untrusted networks, and build routine version-compliance checks into ongoing NetScaler operations.