CVE-2026-88771 — Citrix NetScaler Improper Input Validation Vulnerability

CVE-2026-88771

Citrix NetScaler ADC and Gateway - Pre-Auth Command Injection via Poisoned Log Parsing

What is Citrix NetScaler?

NetScaler ADC (formerly Citrix ADC) is an application delivery controller: a network appliance that sits at the edge of an enterprise network doing load balancing, SSL termination, web application firewalling, and traffic shaping. NetScaler Gateway is the remote-access mode of the same platform, providing VPN and single sign-on for employees reaching internal applications. Both roles put the appliance directly on the internet, in front of everything else, holding TLS private keys, Active Directory service credentials, and live user sessions. That combination is why NetScaler has been a repeat target: compromising one appliance can hand an attacker an authenticated foothold inside the network without touching a single endpoint.

Overview

CVE-2026-88771 is an unauthenticated command injection in NetScaler ADC and NetScaler Gateway. An attacker who can reach the appliance's web interface can cause arbitrary shell commands to run as root, with no credentials, no user interaction, and no non-default feature enabled. Citrix rates it 9.5 Critical under CVSS 4.0; NVD scores it 9.8 under CVSS 3.1.

Citrix disclosed the flaw on 2026-09-27 in bulletin CTX697096, which covers eight NetScaler vulnerabilities (CVE-2026-88771 through CVE-2026-88778). Two of the eight, this one and CVE-2026-88772, were already being exploited as zero-days. The disclosure was unusually chaotic: administrators were being told by national CERTs and suppliers to shut appliances down before any vendor advisory existed. NCSC-NL, the Dutch national cyber security centre, issued a private pre-notification on 2026-09-26 after receiving information from a partner CERT indicating exploitation at multiple Citrix customers worldwide. Citrix filed a notification under the EU Cyber Resilience Act.

What makes this one worse than a typical NetScaler bug is the absence of preconditions. CVE-2026-88772 requires DTLS; the other six in the bulletin depend on specific configurations. CVE-2026-88771 affects every deployment on an affected build in its default configuration. Researcher Kevin Beaumont noted that European government sources had been warning organizations all week and that the attacks had been unfolding through the whole month, meaning exploitation predates the patch by weeks.

Affected Versions

Product Vulnerable Fixed
NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37 14.1-73.37 and later
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-64.23 13.1-64.23 and later
NetScaler ADC 14.1 FIPS before 14.1-73.37 FIPS 14.1-73.37 FIPS and later
NetScaler ADC 13.1 FIPS / NDcPP before 13.1-37.279 13.1-37.279 and later

Branches that have reached end of life receive no fix and must be migrated to a supported build.

Technical Details

The root cause is CWE-20, improper input validation, in a Perl helper script on the appliance (ns_monuploadd_err.pl) that parses log files. The script extracted fields from log lines using a shell pipeline of grep, sed, and awk invoked through backtick interpolation, without strict pattern matching on what it pulled out. Anything that lands in those logs is therefore treated as shell syntax.

Exploitation is two-stage and does not require authentication. First an attacker sends an unauthenticated request to a logging endpoint, for example a POST to /nf/auth/doAuthentication.do with shell metacharacters (semicolons, backticks, redirects) embedded in the login parameter. The request fails authentication, which is the point: the failure is written to the log. Second, when the monitoring daemon next processes that log, the injected metacharacters are executed as root. The delay can be up to 24 hours, though the daemon can be forced to run sooner. Failed logins are not the only sink: request parameters, rate-limit block records, and User-Agent headers also reach the affected logs, giving an attacker several routes to poison them.

The fix in 14.1-73.37 replaces the shell-based parsing with strict regular expression validation. watchTowr reconstructed the vulnerability by diffing the vulnerable 14.1-73.30 build against the patched one.

Discovery

Citrix has not publicly credited an outside researcher. Per the NCSC-NL pre-notification, Citrix identified the vulnerabilities while investigating customer security incidents, making this a discovery driven by incident response rather than proactive research. Information reached NCSC-NL through a European partner CERT, which had confirmed exploitation at multiple Citrix customers worldwide, and NCSC-NL warned Dutch organizations on 2026-09-26, roughly a day before Citrix published. watchTowr, whose CEO Benjamin Harris and threat intelligence specialist Yordan Ganchev publicly confirmed exploitation ahead of the advisory, published the first technical reconstruction after patches shipped.

Exploitation Context

Citrix confirmed exploitation against unmitigated deployments and acknowledged that webshells were planted on compromised appliances. CISA stated that threat actors are exploiting these vulnerabilities globally. Exposure is large: Shadowserver counted more than 20,000 exposed NetScaler instances as of 2026-09-28, and Palo Alto Networks Cortex Xpanse counted over 50,277 exposed instances on 2026-09-27. Confirmed compromises, by contrast, were described by researchers as real but not yet widespread, which is consistent with targeted use rather than mass scanning.

No named threat actor has been attributed. Beaumont assessed the operators as probably nation-state aligned and well resourced, espionage rather than opportunistic. Tenable noted that historically around two-thirds of NetScaler-targeting activity has involved APT groups. CVE-2026-88771 and CVE-2026-88772 are independent vulnerability classes and there is no public evidence they are chained; either alone yields code execution.

Remediation

  1. Upgrade to 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 as applicable. There is no workaround. Patching is the only fix.
  2. Investigate before you patch. Citrix and CISA both warn that updating can destroy forensic evidence. Capture logs, configuration, and disk state first if compromise is plausible.
  3. Run the IOC check. NetScaler Console 14.1-73.36 or later with telemetry enabled exposes an IOC scan on the Security Advisory page. Citrix cautions that the IOCs do not cover every technique, so a clean result is not proof the appliance is uncompromised.
  4. Assume the appliance is compromised if it was internet-facing and unpatched during September 2026. Follow Citrix CTX694799: rotate all credentials the appliance held or could see, replace TLS certificates and keys, terminate all active sessions, and reset local accounts.
  5. Review logs for unexpected outbound connections from the appliance, unexplained gaps in logging, new or modified files in web-accessible paths, and administrative sessions you cannot account for.
  6. Restrict management interface exposure to a dedicated management network. The data plane must stay reachable, but NSIP and management access should never be internet-facing.
  7. Federal civilian agencies were required to remediate by 2026-09-30 under BOD 26-04, a three-day window that reflects the severity of active exploitation, and to perform the forensic triage the directive specifies.

Key Details

PropertyValue
CVE ID CVE-2026-88771
Vendor / Product Citrix — NetScaler
NVD Published2026-09-27
NVD Last Modified2026-09-28
CVSS 3.1 Score9.8
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SeverityCRITICAL
CWE CWE-20 find similar ↗
CISA KEV Added2026-09-27
CISA KEV Deadline2026-09-30
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2026-09-30. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2026-09-26NCSC-NL privately warns customers; watchTowr publicly reports in-the-wild exploitation of an unnamed NetScaler zero-day
2026-09-27Citrix publishes security bulletin CTX697096 with fixed builds; CVE record published
2026-09-27CISA issues alert and adds CVE-2026-88771 to the Known Exploited Vulnerabilities catalog
2026-09-30CISA BOD 26-04 remediation deadline