2026-09-27 16:2CVE-2026-88771NetScaler
PUBLISHED5.2CWE-20

A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Problem type

Affected products

Citrix NetScaler

ADC

< 14.1-73.37 - AFFECTED

< 13.1-64.23 - AFFECTED

< 14.1-73.37 FIPS - AFFECTED

< 13.1.37.279 FIPS and NDcPP - AFFECTED

Gateway

< 14.1-73.37 - AFFECTED

< 13.1-64.23 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-88771
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-88771",
    "assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
    "assignerShortName": "NetScaler",
    "dateUpdated": "2026-09-27T16:02:07.001Z",
    "dateReserved": "2026-09-10T07:14:57.369Z",
    "datePublished": "2026-09-27T16:02:07.001Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
        "shortName": "NetScaler",
        "dateUpdated": "2026-09-27T16:02:07.001Z"
      },
      "datePublic": "2026-09-27T15:51:00.000Z",
      "title": "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands",
      "descriptions": [
        {
          "lang": "en",
          "value": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.<p>This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to&nbsp;<span>an unauthenticated attacker to execute arbitrary commands.&nbsp;</span></p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Citrix NetScaler",
          "product": "ADC",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "patch",
              "lessThan": "14.1-73.37"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "patch",
              "lessThan": "13.1-64.23"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "patch",
              "lessThan": "14.1-73.37 FIPS"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "patch",
              "lessThan": "13.1.37.279 FIPS and NDcPP"
            }
          ]
        },
        {
          "vendor": "Citrix NetScaler",
          "product": "Gateway",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "patch",
              "lessThan": "14.1-73.37"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "patch",
              "lessThan": "13.1-64.23"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-20 Improper input validation",
              "cweId": "CWE-20",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ]
    }
  }
}