By Adam Swan
Publication Date: 2026-10-01 08:28:00
Summary
A critical pre-authentication command injection flaw affects Citrix NetScaler ADC and Gateway appliances. The vulnerability stems from improper input validation in a Perl script, allowing attackers to execute arbitrary system commands with root privileges. CVE-2026-88771 has been actively exploited in the wild as a zero-day vulnerability.
Investigation
Researchers performed a differential analysis of NetScaler builds 14.1-73.30 and 14.1-73.37 to uncover the underlying flaw. They identified unsafe shell interpolation through backticks in the ns_monuploadd_err.pl script, which processes unsanitized log data. By injecting specially crafted HTTP requests into log files, attackers can introduce shell metacharacters that trigger arbitrary command execution when the vulnerable script runs.
Mitigation
Citrix has issued security updates addressing CVE-2026-88771. Organizations should immediately upgrade NetScaler ADC and Gateway…



