ZeroDayAlert

CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

Citrix NetScaler Added to KEV 2026-09-27 Federal due 2026-09-30 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Citrix NetScaler ADC and NetScaler Gateway are vulnerable to unauthenticated command execution due to improper input validation. The record does not specify which versions are affected, whether on-premises or cloud deployments are at greater risk, or the nature of the input vector. You should treat any NetScaler ADC or Gateway in your environment as potentially vulnerable unless you have confirmed a patch or vendor mitigation is in place.

How to check whether this touches you

  • Search your asset inventory for any Citrix NetScaler ADC or NetScaler Gateway appliances, including those managed by third parties or deployed as cloud services.
  • Determine whether each appliance is reachable from untrusted networks (the internet, partner networks, or compromised internal segments); unauthenticated exploitation means network access alone may be sufficient.
  • Check the running software version on each appliance via the management console or CLI; version alone is not proof of patching, as vendors sometimes backport fixes, but it is your first signal.
  • Review recent access logs to the management interface and any exposed service ports to establish a baseline for later forensic review.

What to do

  1. Contact Citrix support immediately to obtain the vendor's recommended mitigation or patch for your specific NetScaler version and deployment model.
  2. If patching is not immediately possible, apply network-level controls: restrict access to the NetScaler management interface and any exposed service ports to trusted networks only, and consider placing the appliance behind a firewall rule that rate-limits or blocks suspicious input patterns.
  3. Enable comprehensive logging of all requests to the NetScaler (management and data plane) and store logs off-device; configure alerts for any error conditions or input validation failures.
  4. If the appliance is internet-facing and a patch is not available within your remediation window, escalate to your security leadership for a decision on temporary service shutdown or product discontinuation per BOD 26-04 guidance.

If you find you were exposed

Exploitation of unauthenticated command execution vulnerabilities typically occurs before public disclosure, so you should assume that any appliance exposed to untrusted networks for more than a few days may have been compromised. Review all available logs from the date of the record's publication (27 September 2026) backwards to the last confirmed patch or baseline configuration change, looking for unusual command execution, new user accounts, or exfiltration of configuration or credential data. Log retention is often the limiting factor; if your logs do not extend back far enough, document that gap and treat the appliance as potentially compromised until further investigation is complete.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-88771 is being exploited. It cannot tell you whether NetScaler is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →