CVE-2026-88771 – Critical Unauthenticated RCE in Citrix NetScaler ADC and Gateway

Key takeaways:

  • Critical CVE-2026-88771 — improper input validation enabling unauthenticated command execution.
  • Citrix NetScaler ADC and Gateway internet-facing appliances are actively exploited.
  • CISA KEV listed; mass exploitation and webshell deployment confirmed globally.
  • Patch immediately; assume compromise for any unpatched instance exposed since late September 2026.

Overview

CVE-2026-88771 is a critical improper input validation flaw in Citrix NetScaler ADC and NetScaler Gateway. Threat actors have exploited it in the wild as a zero-day, achieving remote code execution without authentication. The campaign escalated from stealthy targeting to mass attacks, with defenders reporting webshells planted on compromised appliances.

Technical details

  • CWE-20 — improper input validation.
  • Attack vector: network-accessible, no privileges required, no user interaction.
  • Exploitation results in arbitrary command execution as the appliance user context.
  • Active exploitation confirmed; threat actors observed deploying webshells via crafted requests.

Severity & impact

CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CVSS 4.0: 9.5 Critical. The combination of pre-authentication access and full command execution makes this a top-priority emergency for any organization running exposed NetScaler instances.

Affected products

Citrix NetScaler ADC and NetScaler Gateway before versions 14.1-73.37 and 13.1-64.23 (including FIPS and NDcPP builds). For the complete list of affected versions and CPEs, see the CVE page.

Actionable insights

  • Internet-exposed NetScaler instances are the primary target — verify external visibility now.
  • Finland's NCSC-FI warned that patching alone does not remove an established attacker; assume intrusion if the window was open.
  • Mention activity spiked to hundreds of reports in 48 hours after CISA KEV addition — threat actors are actively scanning.
  • Monitor for anomalous command execution, unexpected webshell files, and suspicious CSS/URL paths used for post-exploitation.
  • For key indicators, exploit activity over time, and detailed signal data, see the CVE page.

Remediation & Mitigation

  1. Patch immediately to Citrix-released versions: ADC/Gateway 14.1-73.37 or 13.1-64.23 (and FIPS/NDcPP equivalents).
  2. If patching is delayed, apply vendor mitigations per advisory and restrict internet exposure.
  3. Conduct forensic triage on all appliances that were unpatched between 2026-09-27 and remediation — look for webshells and unauthorized commands.
  4. Validate remediation by re-scanning for the vulnerability and reviewing logs for exploitation artifacts.
  5. Subscribe to mitigation updates from Citrix and CISA KEV.

Bottom line

CVE-2026-88771 is a critical pre-auth RCE in Citrix NetScaler with confirmed mass exploitation. Patch immediately and assume compromise for any unpatched internet-facing instance.


References

#CVE #Critical #RCE #CISAKEV #CVE202688771 #NetScaler #Citrix