# Citrix NetScaler CVE-2026-88771: A Pre-Auth Command Injection Exploited as a Zero-Day > CVE-2026-88771 is an unauthenticated command-injection flaw in Citrix NetScaler ADC and Gateway, rated 9.5 Critical, exploited in the wild before a fix existed. It ships in the default configuration. Here is what the CTX697096 bulletin covers, how the log-poisoning bug actually works, the fixed builds, and the remediation that patching alone does not give you. Source: https://playciso.com/blog/citrix-netscaler-cve-2026-88771-command-injection · Published: 2026-09-28 · Publisher: PlayCISO (https://playciso.com) Primary source: https://support.citrix.com/article/CTX697096 --- On 27 September 2026, Citrix published security bulletin **CTX697096**, fixing eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them were already being exploited in the wild as zero-days. The most serious, **CVE-2026-88771**, is an unauthenticated command injection that affects the _default_ configuration and runs code as root on the appliance that serves as the remote-access front door for tens of thousands of organisations. This post is a factual walkthrough of what the bulletin covers, how CVE-2026-88771 actually works, the fixed builds, and the remediation steps that patching alone does not give you. The technical mechanism below is described at a conceptual level and is drawn from public reporting — it is written to help defenders find and fix exposure, not to weaponise it. ## What was fixed in CTX697096 The bulletin addresses eight CVEs. Two are confirmed exploited in the wild; the rest depend on specific configurations: - CVE-2026-88771 — improper input validation allowing an unauthenticated attacker to run arbitrary commands. Affects the default configuration. CVSS 4.0 9.5 Critical. Exploited in the wild. - CVE-2026-88772 — memory overflow leading to remote code execution or denial of service when DTLS is enabled (the default for VPN virtual servers). CVSS 4.0 9.5 Critical. Exploited in the wild. - CVE-2026-88773 — HTTP request smuggling (inconsistent interpretation of HTTP requests). CVSS 9.3 Critical. Configuration-dependent. - CVE-2026-88774 — NetScaler ADC/Gateway vulnerability, configuration-dependent. CVSS 7.0 High. - CVE-2026-88775 / 88776 / 88777 — memory-overflow issues, configuration-dependent. CVSS 8.8 High. - CVE-2026-88778 — predictable value derived from previous values; fixed by enabling Enhanced ISN Generation, not by the upgrade alone. CVSS 8.8 High. ## How CVE-2026-88771 works: log poisoning to root The interesting part of this vulnerability is _where_ it lives. Most of the last decade of NetScaler criticals were memory-safety bugs in the packet-processing engine. This one is different: it is a shell command injection in a maintenance **Perl script**, `ns_monuploadd_err.pl`, whose job is to recover the filename of a crashed process core file after a packet-engine failure. The chain, conceptually: - Poison the log. The attacker sends a request containing crafted text in a field that NetScaler writes to its logs — a login field, and (importantly) other logged inputs such as the User-Agent header. Failed logins, rate-limited requests and request parameters can all end up in the logs, so there are many trigger paths, not one endpoint. - The maintenance script parses it. Later, the Perl script reads those log files to extract a crashed core file's name. It expects a value like NSPPE-00-12345 (an engine name plus a numeric process ID) — but it never validates that the parsed text is actually that shape. - Unvalidated text hits a shell. The script interpolates the parsed value into a shell command-substitution (backtick) command that builds a find invocation. Shell metacharacters in the attacker-controlled text — semicolons, backticks, redirection — are then interpreted by the shell as commands, not data. - It runs as root. Nearly everything on a NetScaler runs as root, so the injected command executes with full privileges on the appliance. Two properties make this worse operationally. First, it fires from the **default configuration** and is pre-authentication — no feature toggle, no credentials. Second, execution is **delayed**: the script runs on a schedule (public analysis notes a delay of up to ~24 hours), so the request that plants the payload and the moment code runs are separated in time, which complicates both detection and timeline reconstruction. ## How Citrix fixed it Per public analysis of the patched build, the fix does the obvious, correct things: it replaces the fragile shell pipeline with ordinary Perl file handling, extracts the core-file name only from strictly validated captures (an engine name matching `NSPPE-\d{2}` and a numeric process ID), and runs `find` using an argument list rather than a shell string — so metacharacters can never be interpreted as commands. A final allow-list on the resulting path adds defence-in-depth. In short: validate the input, and never hand untrusted text to a shell. ## Fixed builds (from CTX697096) - NetScaler ADC and NetScaler Gateway 14.1-73.37 and later - NetScaler ADC and NetScaler Gateway 13.1-64.23 and later releases of 13.1 - NetScaler ADC 14.1-FIPS 14.1-73.37 and later releases of 14.1-FIPS - NetScaler ADC 13.1-FIPS / 13.1-NDcPP 13.1-37.279 and later Note that end-of-life versions do not receive fixes; if you are on an unsupported branch, upgrading is the remediation. ## What to do now Because this is pre-auth, internet-reachable, ships in the default configuration and runs as root on your remote-access tier, the response is the same one NetScaler has taught the industry repeatedly — patching is necessary but not sufficient: - Patch to a fixed build on an emergency clock. For an actively exploited pre-auth flaw on an internet-facing gateway, "same day" is the target, not "within 30 days." Citrix advised taking unpatched, exposed appliances offline until they can be updated. - Assume compromise in the exposure window. A stolen session or a dropped implant survives the patch. Terminate active sessions, rotate the credentials and secrets the appliance handled, and re-issue tokens. - Hunt for the artefacts. Because the payload runs as root and public proof-of-concept work writes files to temporary locations, review the appliance for unexpected files (for example under temporary and core-file directories), unexpected outbound connections, webshells, and anomalous authenticated sessions. Review your logs for suspicious values in fields that get logged (login, User-Agent) — those are the poisoning vector here. - Shrink the exposure. Don't expose the management plane to the internet, restrict the gateway to what genuinely needs it, and disable unused features. ## The pattern behind the CVE CVE-2026-88771 is the newest entry in a long, structural story: an internet-facing, pre-authentication appliance you cannot run endpoint detection on, deployed in the highest-value networks, breaking in the same predictable ways. We wrote up that pattern — Shitrix, CitrixBleed, CitrixBleed 2 and the 2025–2026 wave — in [Why Citrix NetScaler Keeps Getting Breached →](/blog/why-citrix-netscaler-keeps-getting-breached), and we track the exploitation density that drives Citrix's fragility score in the [CVSS Vendor Risk Ranking →](/tools/vendor-risk). To size your own blast radius: map remote-access identity exposure with the [Identity Risk Calculator](/tools/identity-risk), and rehearse the "gateway is compromised, tokens are loose" scenario before it is real with the [ransomware readiness tool](/tools/ransomware) and the [NIST CSF assessment](/tools/nist-csf). ## Sources Citrix security bulletin **CTX697096** (fixed versions and CVE list); technical analysis by **watchTowr Labs** ("Oh Look, The Foot Gun Went Off Again", 28 September 2026); reporting by **The Hacker News** and **BleepingComputer**; and **CISA** exploitation advisories. CVE identifiers: CVE-2026-88771 through CVE-2026-88778. ## Frequently asked questions **What is CVE-2026-88771?** An unauthenticated command-injection flaw in Citrix NetScaler ADC/Gateway, CVSS 9.5, affecting the default configuration and exploited in the wild as a zero-day. Fixed in CTX697096 on 27 September 2026. **How does it work?** Log poisoning: attacker-controlled text in a logged field (login, User-Agent) is later parsed by a maintenance Perl script that interpolates the unvalidated value into a shell command, running as root — with execution delayed up to ~24 hours. **What are the fixed versions?** NetScaler ADC/Gateway 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, and 13.1-FIPS/NDcPP 13.1-37.279, and later. **Is patching enough?** No. Terminate sessions, rotate secrets, and hunt after any exploited NetScaler CVE — patching does not undo what already ran or leaked.