What it is
CVE-2026-88771 is an unauthenticated vulnerability affecting Citrix NetScaler ADC, Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before...
Vulnerability report
ADC Remote Code Execution
Citrix NetScaler / ADC · affected before 14.1-73.37
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-88771 is an unauthenticated vulnerability affecting Citrix NetScaler ADC, Gateway. Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Citrix NetScaler / ADC affected before 14.1-73.37.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Citrix
A trusted third party reported exploitation.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Citrix First | 2026-09-27 16:44 UTC |
| CVE | 2026-09-27 20:40 UTC |
| Tenable Blog | 2026-09-27 21:21 UTC |
| CISA | 2026-09-27 21:50 UTC |
| The Hacker News | 2026-09-28 07:30 UTC |
| SOCRadar | 2026-09-28 08:20 UTC |
| CERT Polska | 2026-09-28 08:21 UTC |
| Security Affairs | 2026-09-28 10:21 UTC |
| Rapid7 | 2026-09-28 10:21 UTC |
| watchTowr | 2026-09-28 11:20 UTC |
| NCSC Alerts and Advisories | 2026-09-28 12:20 UTC |
| Palo Alto Unit42 | 2026-09-28 15:21 UTC |
| Qualys ThreatPROTECT | 2026-09-28 16:20 UTC |
| GreyNoise | 2026-09-28 17:21 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
—
Recent mention · The Record
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · The Record
US, UK warn of exploited Citrix NetScaler zero-day bugsThe Record · 28 Sep 2026
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
Recent mention · Qualys ThreatPROTECT
Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)Qualys ThreatPROTECT · 28 Sep 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered agencies to secure their systems against two critical Citrix NetScaler vulnerabilities that have been exploited in attacks. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before September 30, 2026. CVE-2026-88771 This is an improper input validation … Continue reading "Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)"
Recent mention · Palo Alto Unit42
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the WildPalo Alto Unit42 · 28 Sep 2026
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.
Recent mention · NCSC Alerts and Advisories
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler GatewayNCSC Alerts and Advisories · 28 Sep 2026
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
Recent mention · watchTowr
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)watchTowr · 28 Sep 2026
God damn it, we're back in the room again. We'll probably write more here later, but for now, deal with this picture of our favorite software dev, who works at Citrix (we imagine).Citrix, before you ask, we do accept our new volunteer role as an
Recent mention · Rapid7
Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772Rapid7 · 28 Sep 2026
OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, with no additional product features required. The vendor has also indicated that the attack...
Recent mention · Security Affairs
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs · 28 Sep 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote […]
Recent mention · SOCRadar
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772SOCRadar · 28 Sep 2026
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772 Citrix has released emergency security updates for eight vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances, including two cri
Recent mention · TheRegister
Certainties in life: Death, taxes, and critical Citrix vulns under attackTheRegister · 28 Sep 2026
Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
Recent mention · The Hacker News
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws GloballyThe Hacker News · 28 Sep 2026
Ravie LakshmananSep 28, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS score: 9.5) - An improper restriction of operations within the bounds of a memory buffer...
Recent mention · GreyNoise
Swarming Against Citrix 0-Day ExploitationGreyNoise · 28 Sep 2026
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections.
Recent mention · Security Affairs
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-DaySecurity Affairs · 27 Sep 2026
Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The […]
Recent mention · NCSC Security Advisories
NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler GatewayNCSC Security Advisories · 27 Sep 2026
Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties die gebruikmaken van NetScaler-instances zijn ook kwetsbaar voor deze kwetsbaarheden. Deze...
Recent mention · Citrix
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778Citrix · 27 Sep 2026
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis. AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes. Citrix has released updates for...
Recent mention · CERT Polska
Podatności 0-day w urządzeniach Citrix NetScalerCERT Polska · 27 Sep 2026
Zespół CERT Polska informuje o dwóch podatnościach 0-day w urządzeniach Citrix NetScaler, które są aktywnie wykorzystywane do ataków.Na podstawie dostępnych informacji należy założyć, że podatności umożliwiają zdalnemu, nieuwierzytelnionemu atakującemu wykonanie dowolnego kodu na urządzeniu. Szczegóły techniczne nie zostały jeszcze ujawnione, a producent nie opublikował aktualizacji bezpieczeństwa.Z uwagi na aktywnie wykorzystywane luki i brak dostępnej poprawki, rekomendujemy odłączenie urządzeń NetScaler od Internetu oraz śledzenie oficjalnych komunikatów producenta.Biuletyny...
Recent mention · Tenable Blog
Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilitiesTenable Blog · 27 Sep 2026
CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the...
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-09-27 18:15:38 UTC · 0 stars · AI assessment 85%
Timeline
17:21 UTC
Exploitation attested by an external source
16:20 UTC
Exploitation attested by an external source
15:21 UTC
Exploitation attested by an external source
12:20 UTC
Exploitation attested by an external source
11:20 UTC
Exploitation attested by an external source
10:21 UTC
Exploitation attested by an external source
10:21 UTC
Exploitation attested by an external source
08:21 UTC
Exploitation attested by an external source
08:20 UTC
Exploitation attested by an external source
07:30 UTC
Exploitation attested by an external source
21:50 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
21:21 UTC
Exploitation attested by an external source
20:40 UTC
Exploitation attested by an external source
18:15 UTC
Public proof-of-concept code published
16:44 UTC
High-confidence, third-party attested exploitation
16:02 UTC
Vulnerability disclosed publicly
07:14 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-88771
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-88771",
"confidence": "Confirmed",
"cvss_score": 9.5,
"cvss_estimated": false,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}