Citrix NetScaler ADC and NetScaler Gateway are application delivery and secure remote access appliances developed by Cloud Software Group. Organizations deploy them at the network edge to load balance applications, terminate SSL, and provide VPN and ICA remote access to internal resources. They are widely used by enterprises, government agencies, and service providers as the front door to business-critical applications. The Gateway component authenticates remote users through the AAA and nFactor login flow before granting access to internal systems. Because these appliances are internet-facing and sit in front of sensitive networks, they are a frequent target for attackers. Both hardware appliances and virtual or cloud form factors are in common production use.
CVE-2026-88771 is an unauthenticated remote code execution vulnerability affecting NetScaler ADC and NetScaler Gateway. It originates from improper input validation during the appliance's crash-log processing. A value that an unauthenticated user submits during authentication is written verbatim into appliance log files. A scheduled maintenance script later parses those logs and interpolates the attacker-controlled text into a shell command. This allows an attacker to execute arbitrary commands on the appliance with root privileges. Citrix documented the issue in bulletin CTX697096, and it is listed in the CISA Known Exploited Vulnerabilities catalog as actively exploited.
The affected flow starts at the /nf/auth/doAuthentication.do endpoint, where the login parameter is written into appliance logs without sanitization. The vulnerable component is the ns_monuploadd_err.pl scheduler, which recovers core file names from crash records such as the pitboss and NSPPE entries. In vulnerable builds this script constructs a shell command using a backticked find pipeline that includes unvalidated log content. Shell metacharacters present in the logged value are therefore interpreted, producing command injection that runs as root. Execution is asynchronous and fires when the scheduler runs, which can be up to twenty four hours later or when it is triggered manually. No additional feature or special configuration is required, so the default deployment of an affected build is exposed.
Successful exploitation gives an unauthenticated attacker full control of the appliance with root level command execution. From that position an attacker can steal session tokens, stored credentials, and TLS private keys that the appliance holds. The compromised device can be used to pivot into the internal network that sits behind the Gateway. Attackers can install web shells or other implants to maintain access, and this persistence can survive a later firmware upgrade. They can also disrupt or intercept remote access for legitimate users. Because the appliance is a trusted perimeter component, a single compromise can expose the entire organization.
REFERENCES
- https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html
- https://labs.watchtowr.com/oh-look-the-foot-gun-went-off-again-citrix-netscaler-preauth-command-injection-cve-2026-88771/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771
- https://nvd.nist.gov/vuln/detail/CVE-2026-88771
- Upgrade to a fixed build listed in CTX697096, meaning 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1-37.279 or later for FIPS and NDcPP.
- Retire end-of-life 13.0 and 12.1 appliances and migrate to a supported 14.1 build, because no fix is published for those branches.
- Treat any unpatched internet-facing appliance as potentially compromised and hunt for unexpected processes, newly created files, and unusual outbound connections before trusting it again.
- Rotate every secret the appliance handled after patching, including session keys, service account passwords, and TLS private keys, since the fix alone does not remove attacker persistence.
- Forward NetScaler logs to an external SIEM so evidence remains available even if an attacker with code execution tampers with local logs.
- Limit exposure of the management interface and place the authentication endpoints behind additional network controls where possible.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →