Improper Input Validation in Citrix NetScaler ADC and Gateway
CVE-2026-88771
What is CVE-2026-88771?
CVE-2026-88771 represents a significant vulnerability found in Citrix NetScaler ADC and Citrix NetScaler Gateway. These products serve as application delivery controllers and secure remote access gateways, respectively, allowing organizations to manage and optimize application performance while providing secure access for users. The identified vulnerability stems from improper input validation, which can allow unauthenticated attackers to execute arbitrary commands on the affected systems. This could lead to unauthorized access, data leakage, or manipulation of critical application functions, which may severely undermine the security and integrity of organizational networks.
Affected versions include specific releases prior to 14.1-73.37 and 13.1-64.23 for both ADC and Gateway products, posing risks to organizations that maintain outdated software. The presence of this vulnerability without adequate mitigations raises concerns regarding the ability of malicious actors to exploit these systems, potentially leading to extensive security incidents that could disrupt operations.
Potential Impact of CVE-2026-88771
-
Unauthorized Command Execution: The vulnerability permits attackers to execute arbitrary commands without authentication, which could lead to full system compromise and unauthorized manipulation of sensitive data. This ability to run commands can allow attackers to deploy further malicious payloads or pivot to other parts of the network.
-
Data Breach Risks: Organizations utilizing affected versions of Citrix NetScaler ADC and Gateway are at an elevated risk for data breaches. If exploited, attackers could gain access to confidential information, including user credentials and sensitive organizational data, leading to significant financial and reputational damage.
-
Operational Disruption: The exploitation of this vulnerability could result in substantial operational disruptions. Compromised systems may be rendered inoperable, affecting the availability of applications and services that organizations rely on, leading to disruptions in business operations and service delivery to clients.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ADC 0 < 14.1-73.37
ADC 0 < 13.1-64.23
ADC 0 < 14.1-73.37 FIPS
