Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-88773: Citrix NetScaler ADC and Gateway can mishandle web traffic

CVE-2026-88773 · published today
Summary

Older versions of Citrix NetScaler ADC and NetScaler Gateway may treat incoming web requests differently, allowing a single request to be split and processed incorrectly. This can let an attacker bypass security controls or inject unintended commands. Upgrade to the latest software releases or apply the vendor's recommended patches to resolve the issue.

What to do
  • Update citrix netscaler gateway to version 14.1-73.37 FIPS or later.
  • Update citrix netscaler adc to version 14.1-73.37 or later.
Affected software
VendorProductAffected versions
citrix netscaler gateway < 14.1-73.37 FIPS
citrix netscaler adc < 14.1-73.37
Original advisory text
HTTP Request Smuggling
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Severity
9.3 Critical
Type
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Timeline
Published27 Sep 2026
Updated27 Sep 2026
First seen27 Sep 2026
Sources
CVE-2026-88773 · MITRE
Track software like this
Free during beta