## Overview
Citrix disclosed a critical vulnerability, CVE-2026-88771, affecting NetScaler ADC and NetScaler Gateway. This vulnerability arises from improper input validation. It has a CVSS score of 9.5, indicating high severity. Attackers can exploit this flaw to execute arbitrary commands without authentication.
## Technical Details
The vulnerability impacts the following versions of Citrix products:
- NetScaler ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP.
- NetScaler Gateway: before 14.1-73.37 and before 13.1-64.23.
An attacker can leverage this flaw to bypass security controls and run commands on the affected systems. The lack of proper input validation allows for this exploitation.
## Impact
Successful exploitation of CVE-2026-88771 can lead to unauthorized access and control over the affected systems. This could result in data breaches, system manipulation, and further attacks on the network. Organizations using vulnerable versions are at significant risk.
## Mitigation
Defenders should immediately update to the latest versions of Citrix NetScaler ADC and Gateway. The patched versions are 14.1-73.37 and 13.1-64.23 or later. Regularly review and apply security updates to maintain system integrity. Additionally, implement network segmentation to limit exposure and monitor for unusual activity.
CSURFACE Threat Sensor