← Back to search

CVE-2026-88771

9.8 CRITICAL

Published 2026-09-27 · Updated 2026-09-29

AI risk analysis

Summary
This vulnerability allows unauthenticated attackers to execute arbitrary commands due to improper input validation in Citrix NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, respectively.
Exploitability
Exploitation is relatively straightforward given the unauthenticated nature and the ability to execute arbitrary commands.
Blast radius
If exploited, this could lead to complete compromise of the affected NetScaler ADC and Gateway instances, potentially allowing attackers to gain full control over the systems.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Citrix NetScaler ADC 14.1-73.37 or later, and Citrix NetScaler Gateway 14.1-73.37 or later.
rceunauthwebcitrix

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Vendors

citrix

Products

netscaler application delivery controller, netscaler gateway

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.