Cyber & AI intelligence
Wasteland.
Briefs indexed2904
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-88771 2026-09-27

Citrix NetScaler ADC and Gateway Flaw Actively Exploited for Unauthenticated Command Execution (CVE-2026-88771)

"CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026. The Citrix NetScaler ADC and Gateway flaw lets an unauthenticated attacker execute arbitrary commands, and federal…"

CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026. The Citrix NetScaler ADC and Gateway flaw lets an unauthenticated attacker execute arbitrary commands, and federal agencies must act by September 30, 2026.

What Is It

CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway. According to NVD and CISA, an unauthenticated attacker can exploit it to execute arbitrary commands. NVD lists the weakness as CWE-20 (Improper Input Validation). The KEV entry lists CWE-119. The Citrix-supplied CVSS 4.0 score is 9.5 (Critical). Its base metrics are: network attack vector, low attack complexity, attack requirements present, no privileges required, no user interaction, and high impact to the confidentiality, integrity, and availability of the vulnerable system. See the NVD entry for the full CVSS 4.0 vector string.

Why It Matters

CISA's KEV catalog confirms active exploitation. CISA's SSVC assessment also rates exploitation as "active," automatability as "yes," and technical impact as "total." The KEV entry marks forensic triage as required. CISA's notes say that running the Citrix-provided IOCs in the NetScaler console may help identify signs of exploitation, and that customers must conduct forensic triage as directed by BOD 26-04. Known ransomware campaign use is listed as "Unknown."

What's Vulnerable

NetScaler ADC: - Versions before 14.1-73.37 - Versions before 13.1-64.23 - Versions before 14.1-73.37 FIPS - Versions before 13.1-37.279 FIPS and NDcPP

NetScaler Gateway: - Versions before 14.1-73.37 - Versions before 13.1-64.23

Patch Status

Citrix has published a security bulletin covering CVE-2026-88771 through CVE-2026-88778, plus mitigation guidance in CTX697096. The fixed versions are the thresholds listed above. CISA's required action is to apply mitigations according to vendor instructions and to comply with BOD 26-04 and CISA's Forensics Triage Requirements. Where mitigations are unavailable, organizations should follow the BOD 26-04 cloud guidance or stop using the product. Stakeholders must also evaluate each asset's internet exposure. The federal remediation deadline is September 30, 2026. If you suspect a NetScaler ADC is compromised, Citrix provides response steps in CTX694799.

Sources