
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-88771 is a critical improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that allows unauthenticated remote attackers to execute arbitrary commands. It was published on September 27, 2026, and affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability was exploited as a zero-day before patches were released, with active exploitation confirmed by Citrix and CISA. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.5 (Critical) (GitHub Advisory, CISA KEV, Citrix Advisory).
The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in the management or data plane processing of Citrix NetScaler ADC and Gateway appliances. Attackers can exploit this pre-authentication flaw by sending specially crafted network requests to internet-facing NetScaler instances, triggering arbitrary command execution without any credentials. WatchTowr Labs published a detailed technical write-up describing the flaw as a pre-authentication command injection, noting it stems from insufficient sanitization of user-supplied input that is passed to underlying system commands (watchTowr Labs). The CVSS v4.0 vector includes an Attack Requirements of "Present," indicating some deployment-specific preconditions (such as default configuration) must be met, which aligns with reports that default NetScaler configurations are particularly susceptible (GitHub Advisory).
Successful exploitation grants unauthenticated attackers root-level command execution on affected NetScaler appliances, resulting in complete compromise of confidentiality, integrity, and availability. Threat actors have been observed deploying web shells (dubbed "WHIPSHOT") and tunneling malware ("SLAPSHOT") to establish persistent backdoors and pivot into internal networks, targeting government agencies, financial institutions, banks, and telecommunications providers across Europe and North America (BleepingComputer, Security Affairs). Critically, patching alone does not evict attackers who have already established persistence — forensic triage is required post-patching (CISA KEV).
CVE-2026-88771 was exploited as a zero-day for at least three weeks before Citrix released patches, with exploitation beginning as early as early September 2026 (Help Net Security). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026, with a remediation deadline of September 30, 2026 (CISA KEV). Public PoC and detection tools are available on GitHub (e.g., technion/netscaler_scanner, EXEcution-py/CVE-2026-88771-POC, watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771), and a Metasploit module pull request was submitted. Exploitation has been attributed to suspected state-sponsored threat actors, with Mandiant/Google uncovering custom hacking tools including novel C2 frameworks (Google Cloud Blog). The EPSS score is approximately 1.06%, though real-world exploitation is confirmed at mass scale with over 50,000 potentially exposed instances identified (Rapid7).
technion/netscaler_scanner fingerprinting tool to identify internet-facing Citrix NetScaler ADC or Gateway instances running vulnerable versions (ADC < 14.1-73.37 or < 13.1-64.23; Gateway < 14.1-73.37 or < 13.1-64.23).citrix-conf-parse.py to parse the NetScaler configuration and confirm the appliance is in a default or vulnerable configuration state that satisfies the attack requirements (AT:P in CVSS v4.0).Citrix released patches on September 27–28, 2026. Administrators should immediately upgrade to the following fixed versions: NetScaler ADC 14.1-73.37 or later, NetScaler ADC 13.1-64.23 or later, NetScaler ADC 14.1-73.37 FIPS or later, NetScaler ADC 13.1.37.279 FIPS and NDcPP or later, NetScaler Gateway 14.1-73.37 or later, and NetScaler Gateway 13.1-64.23 or later (Citrix Advisory). CISA mandated federal agencies patch by September 30, 2026, and requires forensic triage per BOD 26-04 because patching does not remove backdoors already installed by attackers (CISA KEV). As an interim measure, organizations unable to patch immediately should consider taking internet-facing NetScaler appliances offline or restricting management interface access; network segmentation to limit direct internet exposure is also recommended (Rapid7).
Citrix confirmed active exploitation and released patches on September 27–28, 2026, after security researchers (notably watchTowr and GossiTheDog) had already publicly warned of unpatched zero-day exploitation over the preceding weekend, creating significant community frustration over the delayed official disclosure (CyberScoop). CISA, the UK NCSC, Australia's ACSC, Canada's CCCS, and multiple other national CERTs issued urgent advisories, with the UK NCSC publishing a dedicated PDF advisory (NCSC UK). Google's Mandiant team published threat intelligence on custom malware (WHIPSHOT/SLAPSHOT) and suspected state-sponsored actors, while Unit 42 (Palo Alto Networks), Rapid7, Sophos, and Qualys all published threat briefs (Google Cloud Blog, Unit 42). Social media and security community discussion was extensive, with researchers noting that patching alone is insufficient and that many organizations may still have active backdoors post-patch.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."