{"id":"CVE-2026-88771","published":"2026-09-27T17:16:56.260","lastModified":"2026-09-29T04:18:01.603","description":"Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-20"],"vendors":["citrix"],"products":["netscaler application delivery controller","netscaler gateway"],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771","tags":["US Government Resource"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthenticated attackers to execute arbitrary commands due to improper input validation in Citrix NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, respectively.","exploitability":"Exploitation is relatively straightforward given the unauthenticated nature and the ability to execute arbitrary commands.","blast_radius":"If exploited, this could lead to complete compromise of the affected NetScaler ADC and Gateway instances, potentially allowing attackers to gain full control over the systems.","remediation":"Upgrade to Citrix NetScaler ADC 14.1-73.37 or later, and Citrix NetScaler Gateway 14.1-73.37 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","web","citrix"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:51:14.796Z"}}