← Back to CVE List
CVE-2026-88771NVD
Vulnerability Summary
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
CVSS v4.0 Base Metrics — Score 9.5 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)High
Affected & Patched Versions
- Citrix NetScaler ADC < 14.1-73.37
- Citrix NetScaler ADC < 13.1-64.23
- Citrix NetScaler ADC < 14.1-73.37 FIPS
- Citrix NetScaler ADC < 13.1.37.279 FIPS and NDcPP
- Citrix NetScaler Gateway < 14.1-73.37
- Citrix NetScaler Gateway < 13.1-64.23
- Citrix NetScaler ADC 14.1-73.37
- Citrix NetScaler ADC 13.1-64.23
- Citrix NetScaler ADC 14.1-73.37 FIPS
- Citrix NetScaler ADC 13.1.37.279 FIPS and NDcPP
- Citrix NetScaler Gateway 14.1-73.37
- Citrix NetScaler Gateway 13.1-64.23