CVE-2026-88771
NetScaler ADC/Gateway pre-authentication command injection via the AAA logon endpoint (CVSS 9.5, CISA KEV, exploited as a zero-day)
- Severity
- critical
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway all versions before the fix
- Fixed in
- Citrix NetScaler ADC/Gateway 14.1-73.37
- Detection basis
- Appliance fingerprint
- Shipped rule
- Citrix NetScaler ADC/Gateway: NetScaler ADC/Gateway pre-authentication command injection via the AAA logon endpoint (CVSS 9.5, CISA KEV, exploited as a zero-day)
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-09-28
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-28. Citrix's fix builds: ADC/Gateway 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, 14.1 FIPS before 14.1-73.37, 13.1 FIPS before 13.1.37.279. Exploited before a patch existed - docs/backlog.md D28x predicted this row on 2026-09-24 off the watchTowr pre-disclosure, which carried no ids and so could not be written then. Mechanism (labs.watchtowr.com, 'Oh Look, The Foot Gun Went Off Again'): attacker-controlled `login` in a POST to /nf/auth/doAuthentication.do reaches a shell, unauthenticated, in the DEFAULT configuration. NO EPSS FIELD ON PURPOSE - FIRST had not scored it on the day it landed, and absent means unrated, never zero. FOURTH row on the build-level wall and the first with EVIDENCE rather than an assumption behind it: the watchTowr write-up reverse-engineers the 73.30-vs-73.37 patch diff and demonstrates NO anonymous build-number disclosure anywhere - no header, no HTML comment, no versioned asset path - so the missing version source is a property of the product, not a gap in our reading. Not writable as a `bypass` row either: that arm is GET-only and side-effect-free by construction, while proving this bug means executing a command on someone else's appliance. Advisory observation naming the id.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →Review the measured benchmark, then use the verified remediation process.