CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability
Summary
Citrix NetScaler ADC and NetScaler Gateway have an improper input validation vulnerability allowing unauthenticated command execution. The CISA KEV directive mandates applying vendor-provided mitigations by September 30, 2026, with specific guidance for cloud services and a potential requirement to discontinue use if mitigations are unavailable.
IFF Assessment
This vulnerability allows an unauthenticated attacker to execute arbitrary commands, posing a significant risk to affected systems.
Severity
The vulnerability allows for arbitrary command execution by an unauthenticated attacker. This has a high attack vector, high complexity, low privileges required, and a critical impact on confidentiality, integrity, and availability, leading to a CVSS score of 9.8 (Critical).
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
This critical vulnerability in Citrix NetScaler products requires immediate attention from defenders. Organizations must prioritize applying vendor-provided mitigations and adhere to CISA's directives for risk-based security updates. The potential for unauthenticated command execution makes this a prime target for attackers seeking to gain control of network infrastructure.