NetScaler unauth RCE exploited in the wild (CVE-2026-88771)
CVE-2026-88771
CVE-2026-88771: unauthenticated remote code execution in NetScaler ADC and Gateway (CVSS 9.5), exploited in the wild. Update to 14.1-73.37 or 13.1-64.23.
Actively exploited in the wild - CVE-2026-88771 is a critical unauthenticated remote code execution flaw in Citrix NetScaler ADC (before 14.1-73.37, before 13.1-64.23, and the FIPS/NDcPP builds) and NetScaler Gateway (before 14.1-73.37, before 13.1-64.23) that lets any attacker on the network run arbitrary commands on the appliance. Citrix has shipped fixes; if your NetScaler is internet-facing and unpatched, treat it as compromised.
Overview
CVE-2026-88771 is an improper input validation flaw in Citrix NetScaler ADC and NetScaler Gateway. NetScaler appliances sit at the edge of the network, terminating VPN, ICA proxy, and load-balancing traffic. Because the vulnerable code path is reachable before authentication, an attacker needs no credentials and no user interaction: they send a crafted request over the network and the appliance executes commands on their behalf.
The CVSS score is 9.5. Attack vector is network, complexity is low, privileges required are none, and user interaction is none. That combination is the worst case for an edge device, because exploitation scales trivially across every exposed host.
Impact
Successful exploitation grants arbitrary command execution with the privileges of the NetScaler service, which on these appliances is effectively full control of the system. From there an attacker can read configuration and secrets, including session data and stored credentials, pivot into internal networks reachable from the appliance, and establish persistence. CISA has added CVE-2026-88771 to the Known Exploited Vulnerabilities catalog, confirming real-world attacks are underway - this is not a theoretical risk.
Remediation and mitigation
Patch immediately. Citrix fixed this in the following builds:
- NetScaler ADC and Gateway: 14.1-73.37 and later, or 13.1-64.23 and later
- FIPS and NDcPP builds: 14.1-73.37 FIPS or later, 13.1.37.279 FIPS or later
If you cannot patch on your maintenance window, restrict management and VPN interfaces to trusted IP ranges, block unnecessary external access, and monitor for anomalous command execution or outbound connections from the appliance. Because this is a KEV-listed flaw with no authentication barrier, assume any unpatched, internet-facing system has already been probed - review logs and rotate credentials and secrets after patching.
Security Insight
NetScaler has become a recurring target, and this follows the same pattern seen with Citrix Bleed 2, where edge appliances were exploited for initial access and then handed off to ransomware crews. The lesson from the earlier NetScaler memory disclosure campaign is that these devices are attacker infrastructure magnets: they are exposed by design, hard to instrument, and often patched slowly. An unauthenticated RCE on the same product line, now in KEV, should be treated as an emergency rather than a routine maintenance item.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may ...
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parame...
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * ...
PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules....