CVE-2026-88773

Published Sep 27, 2026

Last updated 5 hours ago

CVSS critical 9.3
Citrix NetScaler ADC
Citrix NetScaler Gateway

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-88773 is an HTTP request smuggling vulnerability found in Citrix NetScaler ADC and Citrix NetScaler Gateway products. This flaw arises from an inconsistent interpretation of HTTP requests. The vulnerability specifically impacts appliances configured with load balancing, content switching, VPN, or authentication virtual servers that are of type HTTP or SSL. Affected versions include NetScaler ADC and NetScaler Gateway before 14.1-73.37, before 13.1-64.23, and specific FIPS and NDcPP builds.

Description
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
NVD status
Analyzed
Products
netscaler_application_delivery_controller, netscaler_gateway

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
10
Impact score
5.8
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
CWE-444

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

3

  1. 🚨 Citrix NetScaler ADC and Gateway HTTP request smuggling (CVE-2026-88773) Critical Vulnerability Alert! Citrix NetScaler ADC and NetScaler Gateway is affected by CVE-2026-88773. 🔍 Identify Targets via ZoomEye: Search Dork: app="Citrix NetScaler" Exposure: 239.2k instanc

    @zoomeyebot

    28 Sept 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://t.co/afDGMYO34t KEV↓ Critical Zero-Day Vulnerabilities Exploited i

    @taku888infinity

    27 Sept 2026

    1131 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  3. CVE-2026-88773 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affec… https://t.co/dYSh2jTZpH

    @CVEnew

    27 Sept 2026

    1242 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Citrix releases patches for actively exploited Netscaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773) allowing unauthenticated RCE. Patch now and check for webshells! #CyberSecurity #CVE #Netscaler https://t.co/Egxsxsup2q

    @Npj8448

    27 Sept 2026

    203 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://t.co/1jRJkVAemq CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, https:

    @DarkWebInformer

    27 Sept 2026

    11733 Impressions

    17 Retweets

    65 Likes

    19 Bookmarks

    3 Replies

    0 Quotes

Configurations