CVE-2026-88771

CRITICAL CISA KEV TTE Zero-Day Pub 27/09 Upd 28/09

Overview

This vulnerability is an improper input validation flaw in Citrix NetScaler ADC and Gateway components. The root cause lies in insufficient sanitization of user-supplied input within specific request handling routines, allowing malicious data to bypass validation checks. Affected components include NetScaler ADC versions prior to 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP variants, as well as NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23.

Vulnerability Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Impact

An unauthenticated attacker can exploit this vulnerability to execute arbitrary commands on the affected Citrix NetScaler ADC or Gateway systems. This allows full control over the device, enabling data exfiltration, configuration manipulation, or lateral movement within the network. No authentication or user interaction is necessary, making it highly exploitable remotely. The consequence is a complete compromise of the device and potentially the broader network infrastructure it supports.

Solution

Citrix has released security updates addressing this vulnerability in NetScaler ADC and Gateway versions 14.1-73.37 and 13.1-64.23. Administrators should apply these patches promptly to affected systems. Detailed patch instructions and advisory information are available at Citrix Support article CTX697096 (https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096). No alternative workarounds are documented; patching is the recommended mitigation.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products

No CPE information available.

Exploits

No exploits found for this CVE.

Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest VERY HIGH
Sightings Extensive activity

Threat Feed

5 events
2026-09-28
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-09-27
Threat Sensor Sighting — Considerable activity

Sighting activity recorded

2026-09-27
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2026-09-27
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: Citrix, product: NetScaler ADC and NetScaler Gateway

Detected as Exploited in the Wild (5907 sightings)

Active exploitation confirmed with 5907 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Improper Input Validation
100% input_validation
Authentication Bypass
40% auth_bypass

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-101 Server Side Include (SSI) Injection
54%
High High
CAPEC-88 OS Command Injection
54%
High High
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
51%
High High
CAPEC-14 Client-side Injection-induced Buffer Overflow
48%
Medium High
CAPEC-22 Exploiting Trust in Client
48%
High High

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-88771
support.citrix.com
GitHub CVE
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
cisa.gov
NVD API
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771