CVE-2026-88773
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
- Published Sep 27, 2026
- CVSS 9.3 critical
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-88771, CVE-2026-88772 and others) JPCERT/CC ·
- Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code Execution CIS MS-ISAC ·
- Citrix security advisory (AV26-965) Canadian Centre for Cyber Security ·
- Multiple vulnerabilities in Citrix NetScaler ADC and Gateway CERT-FR ·
- Critical Vulnerabilities in Citrix NetScaler ADC and Gateway CERT-EU ·
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway CISA ·