Citrix NetScaler was vulnerable to a pre-authentication remote code execution (CVE-2026-88771) exploited through log injection. Attackers embedded base64-encoded bash commands in HTTP User Agent headers and authentication logs; when the ns_monuploadd_err.pl script processed logs, it executed unsanitized grep results, allowing arbitrary command execution and web shell deployment.
Citrix NetScaler ADC and Gateway are affected by multiple remote code execution vulnerabilities (CVE-2026-88771 through CVE-2026-88777). Cloud Software Group urges customers to install updates immediately, with some vulnerabilities affecting all deployments by default while others require specific configurations like DTLS or HTTP to be exploited.