## Overview
CISA added CVE-2026-88771 to its Known Exploited Vulnerabilities (KEV) list on September 27, 2026. This vulnerability affects Citrix NetScaler ADC and Gateway products. It allows unauthenticated attackers to execute arbitrary commands. The urgency of this addition reflects evidence of active exploitation in the wild.
## Technical Details
The vulnerability stems from improper input validation in Citrix NetScaler ADC and Gateway. Affected versions include ADC versions before 14.1-73.37, 13.1-64.23, and their FIPS variants. For the Gateway, versions before 14.1-73.37 and 13.1-64.23 are impacted. Attackers can exploit this flaw without authentication, making it particularly dangerous.
## Impact
Successful exploitation of CVE-2026-88771 can lead to unauthorized command execution on vulnerable systems. This could allow attackers to gain control over affected devices, potentially leading to data breaches or further network compromise. Organizations using these versions of Citrix NetScaler are at high risk, especially given the CVSS score of 9.5, indicating critical severity.
## Mitigation
Defenders should immediately update their Citrix NetScaler ADC and Gateway products to the latest versions. Citrix has released patches addressing this vulnerability. Organizations must prioritize these updates to protect against potential exploitation. Regularly auditing and monitoring systems for unusual activity is also recommended to detect any attempts to exploit this vulnerability.
CSURFACE Threat Sensor