CVE-2026-88771

Summary

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Affected Software

VendorProductVersion RangeStatus
Citrix NetScalerADC0 < 14.1-73.37affected
Citrix NetScalerADC0 < 13.1-64.23affected
Citrix NetScalerADC0 < 14.1-73.37 FIPSaffected
Citrix NetScalerADC0 < 13.1.37.279 FIPS and NDcPPaffected
Citrix NetScalerGateway0 < 14.1-73.37affected
Citrix NetScalerGateway0 < 13.1-64.23affected

Weaknesses

  • CWE-20: CWE-20 Improper input validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References