Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-88771: Citrix NetScaler ADC and Gateway allow remote command execution
CVE-2026-88771 · published today
Summary
Older versions of Citrix NetScaler ADC and NetScaler Gateway do not properly check input, so someone on the network can run commands on the device without logging in. This could let an attacker take control of the appliance and affect your services. Update to the latest supported version or apply the vendor's security patch as soon as possible.
What to do
- Update citrix netscaler adc to version 14.1-73.37 or later.
- Update citrix netscaler gateway to version 14.1-73.37 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| citrix netscaler | adc | < 14.1-73.37 |
| citrix netscaler | gateway | < 14.1-73.37 |
Original advisory text
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Severity
9.5
Critical
CVSS 4.0: 9.5 (NVD)
Type
CWE-20Improper Input Validation
Timeline
Published27 Sep 2026
Updated27 Sep 2026
First seen27 Sep 2026
Track software like this
Free during beta