CVE-2026-88771 – Critical Unauthenticated RCE in Citrix NetScaler ADC and Gateway
Key takeaways:
- Critical CVE-2026-88771 — improper input validation enabling unauthenticated command execution.
- Citrix NetScaler ADC and Gateway internet-facing appliances are actively exploited.
- CISA KEV listed; mass exploitation and webshell deployment confirmed globally.
- Patch immediately; assume compromise for any unpatched instance exposed since late September 2026.
Overview
CVE-2026-88771 is a critical improper input validation flaw in Citrix NetScaler ADC and NetScaler Gateway. Threat actors have exploited it in the wild as a zero-day, achieving remote code execution without authentication. The campaign escalated from stealthy targeting to mass attacks, with defenders reporting webshells planted on compromised appliances.
Technical details
- CWE-20 — improper input validation.
- Attack vector: network-accessible, no privileges required, no user interaction.
- Exploitation results in arbitrary command execution as the appliance user context.
- Active exploitation confirmed; threat actors observed deploying webshells via crafted requests.
Severity & impact
CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CVSS 4.0: 9.5 Critical. The combination of pre-authentication access and full command execution makes this a top-priority emergency for any organization running exposed NetScaler instances.
Affected products
Citrix NetScaler ADC and NetScaler Gateway before versions 14.1-73.37 and 13.1-64.23 (including FIPS and NDcPP builds). For the complete list of affected versions and CPEs, see the CVE page.
Actionable insights
- Internet-exposed NetScaler instances are the primary target — verify external visibility now.
- Finland's NCSC-FI warned that patching alone does not remove an established attacker; assume intrusion if the window was open.
- Mention activity spiked to hundreds of reports in 48 hours after CISA KEV addition — threat actors are actively scanning.
- Monitor for anomalous command execution, unexpected webshell files, and suspicious CSS/URL paths used for post-exploitation.
- For key indicators, exploit activity over time, and detailed signal data, see the CVE page.
Remediation & Mitigation
- Patch immediately to Citrix-released versions: ADC/Gateway 14.1-73.37 or 13.1-64.23 (and FIPS/NDcPP equivalents).
- If patching is delayed, apply vendor mitigations per advisory and restrict internet exposure.
- Conduct forensic triage on all appliances that were unpatched between 2026-09-27 and remediation — look for webshells and unauthorized commands.
- Validate remediation by re-scanning for the vulnerability and reviewing logs for exploitation artifacts.
- Subscribe to mitigation updates from Citrix and CISA KEV.
Bottom line
CVE-2026-88771 is a critical pre-auth RCE in Citrix NetScaler with confirmed mass exploitation. Patch immediately and assume compromise for any unpatched internet-facing instance.
References
- Citrix Advisory: CTX697096
- CISA KEV: Known Exploited Vulnerabilities Catalog
#CVE #Critical #RCE #CISAKEV #CVE202688771 #NetScaler #Citrix
