Skip to content

security_identifier

CVE-2026-88771

Improper input validation vulnerability in NetScaler ADC and NetScaler Gateway allowing unauthenticated arbitrary command execution, rated CVSS 9.5.

Current clusters

security18 publishers

Citrix patches two NetScaler zero-days that attackers used before any fix existed

Citrix shipped fixes on September 27 for NetScaler flaws CVE-2026-88771 and CVE-2026-88772, both rated 9.5 and exploited on unpatched appliances. Exploitation began before the fix, at a date Citrix has not given, so affected appliances need an intrusion check as well as an upgrade.

Perspective Coverage

17 publishers
Builder
Builder 12%
Operator
Operator 81%
Investor
Investor 7%

Reality

Evidence82
Adoption70
Hype gap+8
Incentives35
Confidence78
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72