Skip to content
VulniPulse
Advisory severityCritical9.5NetScaler (Citrix) Exploited CISA KEV

Critical [CVE-2026-88771] A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

This critical-severity NetScaler (Citrix) advisory covers CVE-2026-88771 affecting Gateway.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-88771 Source published Source updated

VulniPulse record published

Affected products & platforms
NetScaler (Citrix)NetScaler Gateway
Open source advisory

Android app · Google Play

Monitor future NetScaler (Citrix) CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CISA Known Exploited Vulnerability

Listed:
Sep 27, 2026 · federal remediation due Sep 30, 2026
Required action:
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Ransomware use:
Unknown

KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.

Affected versions
  • ADC before 14.1-73.37
  • ADC before 13.1-64.23
  • ADC before 14.1-73.37 FIPS
  • ADC before 13.1.37.279 FIPS and NDcPP
  • Gateway before 14.1-73.37
  • Gateway before 13.1-64.23

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 14.1-73.37
  • 13.1-64.23
  • 14.1-73.37 FIPS
  • 13.1.37.279 FIPS and NDcPP

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation

Upgrade to a fixed release: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS and NDcPP. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.