CVE-2026-88771

Received
Published: 27 Sept 2026, 16:02
Last modified:27 Sept 2026, 19:57

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.5 CRITICAL
v4.0 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Sept 2026, 16:02
Published
Vulnerability first disclosed
27 Sept 2026, 19:57
Last Modified
Vulnerability information updated

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVSS Metrics

  • v4.0•CRITICAL•Score: 9.5CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • v4.0•CRITICAL•Score: 9.5CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Techniques & Countermeasures

  • CWE-20•Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • citrix netscaler•adc

    < 14.1-73.37 | < 13.1-64.23 | < 14.1-73.37 FIPS | < 13.1.37.279 FIPS and NDcPP

  • citrix netscaler•gateway

    < 14.1-73.37 | < 13.1-64.23

References (2)