CVE-2026-88771

Published Sep 27, 2026

Last updated 3 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-88771 is identified as an improper input validation vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway products. This flaw enables an unauthenticated attacker to execute arbitrary commands on affected systems. The vulnerability impacts all deployments of NetScaler ADC and NetScaler Gateway, and no specific additional features are required for it to be exploitable. Citrix confirmed that this vulnerability, alongside CVE-2026-88772, has been actively exploited in the wild on unmitigated NetScaler deployments. The company released security updates to address these issues, which were attacked before a public fix was available. NetScaler ADC and NetScaler Gateway appliances are commonly deployed at the edge of enterprise networks, handling functions such as VPN, remote access, load balancing, and user authentication.

Description
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

37

  1. 🚨 #ALERT — CITRIX NETSCALER RCE FLAWS CONFIRMED ACTIVELY EXPLOITED September 27, 2026 — Citrix officially confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 against unmitigated NetScaler deployments. DISCLOSED BY: Citrix / Cloud Software Group CONFIRMED EXPLOIT

    @Python_s_

    27 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨Citrixよりゼロデイに関連した公式パッチリリースあり(CVE-2026-88771~88778) CVE-2026-88771 / 88772(CVSS 9.5)がRCEに繋がるもので悪用を既に観測 88771は前提条件なし、88772はDTLS有効が条件(VPN vServerはデフォルトON) h

    @KesaGataMe0

    27 Sept 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Citrix confirmed two new NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5 and exploited before patches were available. https://t.co/nxieVgzIEa

    @DanielMiessler

    27 Sept 2026

    1035 Impressions

    1 Retweet

    5 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🚨 Citrix releases patches for actively exploited Netscaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773) allowing unauthenticated RCE. Patch now and check for webshells! #CyberSecurity #CVE #Netscaler https://t.co/Egxsxsup2q

    @Npj8448

    27 Sept 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Citrix has confirmed active exploitation of two NetScaler RCE flaws. CVE-2026-88771 | CVSS 9.5 CVE-2026-88772 | CVSS 9.5 8 vulnerabilities disclosed. Patches are now available. 🔎 CVE-2026-88771: https://t.co/z1tASkrYiD CVE-2026-88772: https://t.co/xS0uOfs7VF

    @exploitgrid

    27 Sept 2026

    196 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Citrix says exploitation of NetScaler ADC and Gateway flaws CVE-2026-88771 and CVE-2026-88772 has been observed. On 14.1-73.32 or 13.1-63.21? Still affected. Minimum fixed: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1-37.279 FIPS/NDcPP. https://t.co/PJzcSCltFd #NetScaler

    @MassPirate

    27 Sept 2026

    107 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CITRIX NETSCALER — OFFICIAL PATCHES FOR TWO EXPLOITED RCE ZERO-DAYS (CVE-2026-88771 / CVE-2026-88772) Cloud Software Group (Citrix) published security bulletin CTX697096 covering eight NetScaler ADC / NetScaler Gateway flaws, including two critical remote code execution h

    @DailyDarkWeb

    27 Sept 2026

    3093 Impressions

    1 Retweet

    14 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  8. ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://t.co/1jRJkVAemq CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, https:

    @DarkWebInformer

    27 Sept 2026

    6779 Impressions

    11 Retweets

    35 Likes

    14 Bookmarks

    2 Replies

    0 Quotes

  9. 🚨 #ALERT — CITRIX NETSCALER RCE ZERO-DAYS CONFIRMED ACTIVELY EXPLOITED September 27, 2026 — Citrix officially confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments. DISCLOSED BY: Citrix / Cloud Software Group CONFIRMED EXPLOITE

    @Python_s_

    27 Sept 2026

    100 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Citrix confirms two actively exploited zero-days hitting every NetScaler deployment (both CVSS 9.5). CVE-2026-88771: improper input validation gives an unauthenticated attacker arbitrary command execution, with no optional feature required, every default install is exposed. http

    @vuln_tracker

    27 Sept 2026

    199 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Citrix NetScaler ADC/Gatewayのゼロデイ2件について公式情報が出た。CVE-2026-88771及びCVE-2026-88772はいずれもCVSSスコア9.5で、前者は無条件で刺さり、後者はDTLSが有効であることが条件(VPN仮想サーバでは既定で有効)

    @__kokumoto

    27 Sept 2026

    679 Impressions

    1 Retweet

    4 Likes

    1 Bookmark

    1 Reply

    1 Quote

  12. ‼️ تحذير عاجل اذا تستخدم Citrix NetScaler تواصل مع مزود الخدمة وحدث لاخر نسخه لوجود ثغرتين Zero-Day تستغل حالياً CVE-2026-88771 CVE-2026-88772 المصدر https://t.co/p4437icQtN https://t.co/SvnP19

    @buhaimedi

    27 Sept 2026

    1394 Impressions

    0 Retweets

    6 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  13. CVE-2026-88771 and CVE-2026-88772: #Citrix has patched two exploited NetScaler ADC/Gateway zero-days, both with a CVSS score of 9.5. One gives unauthenticated command execution on default configurations. 🧵 https://t.co/QVuCz33ZFw

    @cyberkendra

    27 Sept 2026

    135 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  14. 🚨 CRITICAL NetScaler Security Alert: Active exploitation observed. ⚠️ Citrix reports exploitation of CVE-2026-88771 and CVE-2026-88772. CVE-2026-88771 affects all NetScaler ADC/Gateway deployments, including default configurations. 🔗 Update now: https://t.co/zULa20zvy

    @FerroqueSystems

    27 Sept 2026

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. ‼️ BREAKING: Citrix confirms two NetScaler flaws have been exploited and has released fixes. CVE-2026-88771 and CVE-2026-88772 were observed exploited on unmitigated deployments. The new advisory covers eight CVEs affecting NetScaler ADC and Gateway. New Details → https:

    @TheHackersNews

    27 Sept 2026

    19175 Impressions

    36 Retweets

    144 Likes

    31 Bookmarks

    7 Replies

    2 Quotes

  16. 🚨 Patch your NetScaler NOW. CTX697096: 8 new CVEs in ADC/Gateway. 2 unauth RCEs exploited in the wild: 🔴 CVE-2026-88771 (9.5) – all configs, no workaround 🔴 CVE-2026-88772 (9.5) – DTLS, on by default Fixed: 14.1-73.37 / 13.1-64.23 August builds NOT fixed. #NetScal

    @_POPPELGAARD

    27 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 Patch your NetScaler NOW. CTX697096: 8 new CVEs in ADC/Gateway. 2 unauth RCEs exploited in the wild: 🔴 CVE-2026-88771 (9.5) – all configs, no workaround 🔴 CVE-2026-88772 (9.5) – DTLS, on by default Fixed: 14.1-73.37 / 13.1-64.23 August builds NOT fixed. #NetScal

    @_POPPELGAARD

    27 Sept 2026

    42 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Official comms and patches from Citrix are out! Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. https://t.co/aUCjUhw8H1

    @BertJanCyber

    27 Sept 2026

    3231 Impressions

    11 Retweets

    28 Likes

    10 Bookmarks

    1 Reply

    1 Quote

  19. Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://t.co/0JS7KidPd8

    @citrix

    27 Sept 2026

    24852 Impressions

    81 Retweets

    147 Likes

    46 Bookmarks

    9 Replies

    19 Quotes