CVE-2026-88771
9.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Citrix NetScaler | ADC | 0 < 14.1-73.37 | affected |
| Citrix NetScaler | ADC | 0 < 13.1-64.23 | affected |
| Citrix NetScaler | ADC | 0 < 14.1-73.37 FIPS | affected |
| Citrix NetScaler | ADC | 0 < 13.1.37.279 FIPS and NDcPP | affected |
| Citrix NetScaler | Gateway | 0 < 14.1-73.37 | affected |
| Citrix NetScaler | Gateway | 0 < 13.1-64.23 | affected |
Weaknesses
- CWE-20: CWE-20 Improper input validation
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: active
- Automatable: yes
- Technical Impact: total
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.