Description
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Published: 2026-09-27
Score: 9.5 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Improper input validation in Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to construct malicious input that bypasses security checks and executes arbitrary commands on the underlying host. This flaw can lead to complete control of the appliance, enabling attackers to exfiltrate data, modify configurations, or pivot to other network resources. The vulnerability is classified as a Remote Code Execution flaw.

Affected Systems

Affected systems include Citrix NetScaler ADC versions prior to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP, as well as Citrix NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23. All firmware revisions listed are impacted and require update or mitigation.

Risk and Exploitability

The CVSS score of 9.5 signals a critical severity, and while the EPSS score is not available, the lack of a KEV listing does not reduce the risk. Based on the description, the flaw can be exploited remotely over the network by sending crafted requests to the appliance’s web interface, with no authentication required. The high severity and broad availability of the attack vector make timely remediation essential.

Generated by OpenCVE AI on September 27, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Citrix patch that fixes the input validation flaw on all affected ADC and Gateway firmware revisions.
  • If an immediate patch is unavailable, isolate the NetScaler devices behind restricted firewall rules or block unused management ports to prevent unauthenticated external access.
  • Deploy network segmentation so that only trusted hosts can reach the ADC/Gateway management interfaces and monitor traffic for suspicious requests.

Generated by OpenCVE AI on September 27, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 27 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Title A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-09-27T19:57:15.713Z

Reserved: 2026-09-10T07:14:57.369Z

Link: CVE-2026-88771

cve-icon Vulnrichment

Updated: 2026-09-27T17:39:21.929Z

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:56.260

Modified: 2026-09-27T20:16:50.083

Link: CVE-2026-88771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation