peter bassill · operator
$ cve CVE-2026-88771 JSON

CVE-2026-88771 KEV

?
unscored · CVSS

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-30.

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Scoring

CVSSunscored
EPSS—
WeaknessCWE-20
On CISA KEVyes — remediate by 2026-09-30
Public exploitnone known
Published2026-09-27
Last modified2026-09-27

CISA KEV

NameCitrix NetScaler Improper Input Validation Vulnerability
Added2026-09-27
Due2026-09-30
Vendor / productCitrix / NetScaler
Ransomware usenone reported

References

→ the Explorer  ·  watch your stack  ·  NVD