CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that permits unauthenticated remote command execution as root. Attacker-controlled text submitted through authentication fields or HTTP User-Agent headers is logged and subsequently processed without adequate sanitization by the admautoregd daemon, allowing injected shell commands to execute. Execution is delayed until the relevant log-processing job runs, potentially hours after the malicious request. All deployment configurations running affected builds are exposed, including default configurations. Affected releases include ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, ADC 14.1-FIPS before 14.1-73.37 FIPS, and ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279. Exploitation was observed before public disclosure on September 27, 2026.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (12 hidden).
This is a standalone exploit-analysis and evidence repository for CVE-2026-88771, not a framework module. It documents a cross-component, pre-auth root command-injection chain affecting Citrix NetScaler ADC 14.1-66.59 and 14.1-72.61. An unauthenticated NITRO login POST accepts a username with only a less-than-128-byte length check. A failed login is recorded in /var/log/ns.log, and the root-run admautoregd telemetry worker periodically calls ns_monuploadd_err.pl -WR. In vulnerable builds, that Perl branch extracts an NSPPE-related token from logs using grep/sed/awk and interpolates it unquoted into a backtick-executed find command, allowing shell syntax from the logged input to run as root. The claimed fix in 14.1-73.37 removes the production PE-failure caller and replaces shell-based parsing/execution with strict parsing and argument-vector invocation. The tree primarily contains Markdown investigation reports, firmware hashes, Ghidra decompilations, Python/Perl/PHP/shell evidence, and old/new mastools telemetry sources. README and analysis files reference working and weaponized PoCs under poc/, but those PoC files are not included in the supplied file inventory; the included SAFE_LOG_PARSER_REPRO.md is deliberately non-executing. Static evidence is detailed and internally consistent; the stated live root-marker validation remains operator-reported because supporting request, log, trace, and stat artifacts are absent.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
650 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability with a CVSS score of 9.5 mentioned as background to the main advisory. Citrix confirmed active exploitation on unpatched systems and urged customers to install relevant updates. Its technical cause and specific affected products are not stated.
A NetScaler vulnerability under confirmed active exploitation. The article does not describe its technical mechanism or affected version ranges, but instructs administrators to consult separate Citrix advisories, apply fixes, and assess appliances for compromise.
A vulnerability affecting NetScaler ADC and NetScaler Gateway, mentioned as background because it is actively exploited. Its technical details are not provided.
An actively exploited NetScaler remote code execution zero-day patched in September. The pair of vulnerabilities enabled deployment of web shells and tunneling malware, credential theft, root access, and movement into victims' internal networks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.