CVE-2026-88773
Published Sep 27, 2026
Last updated 5 hours ago
AI description
CVE-2026-88773 is an HTTP request smuggling vulnerability found in Citrix NetScaler ADC and Citrix NetScaler Gateway products. This flaw arises from an inconsistent interpretation of HTTP requests. The vulnerability specifically impacts appliances configured with load balancing, content switching, VPN, or authentication virtual servers that are of type HTTP or SSL. Affected versions include NetScaler ADC and NetScaler Gateway before 14.1-73.37, before 13.1-64.23, and specific FIPS and NDcPP builds.
- Description
- Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
- Source
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- NVD status
- Analyzed
- Products
- netscaler_application_delivery_controller, netscaler_gateway
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 10
- Impact score
- 5.8
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Severity
- CRITICAL
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- CWE-444
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
3
🚨 Citrix NetScaler ADC and Gateway HTTP request smuggling (CVE-2026-88773) Critical Vulnerability Alert! Citrix NetScaler ADC and NetScaler Gateway is affected by CVE-2026-88773. 🔍 Identify Targets via ZoomEye: Search Dork: app="Citrix NetScaler" Exposure: 239.2k instanc
@zoomeyebot
28 Sept 2026
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778 https://t.co/afDGMYO34t KEV↓ Critical Zero-Day Vulnerabilities Exploited i
@taku888infinity
27 Sept 2026
1131 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
CVE-2026-88773 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affec… https://t.co/dYSh2jTZpH
@CVEnew
27 Sept 2026
1242 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Citrix releases patches for actively exploited Netscaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88773) allowing unauthenticated RCE. Patch now and check for webshells! #CyberSecurity #CVE #Netscaler https://t.co/Egxsxsup2q
@Npj8448
27 Sept 2026
203 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼️ Citrix has released a security bulletin regarding zero-day attacks targeting Citrix NetScaler ADC and Citrix NetScaler Gateway. More info: https://t.co/1jRJkVAemq CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, https:
@DarkWebInformer
27 Sept 2026
11733 Impressions
17 Retweets
65 Likes
19 Bookmarks
3 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"matchCriteriaId": "6BC2D462-9ABE-4024-8E46-8D265C0B19FB",
"versionEndExcluding": "13.1-64.23",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"matchCriteriaId": "2DB314FE-3886-4ABD-A820-B8A70EBB23A6",
"versionEndExcluding": "13.1.37.279",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
"matchCriteriaId": "FCFFA1B3-87CE-4CC8-990E-D3CE0B55CD45",
"versionEndExcluding": "13.1.37.279",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"matchCriteriaId": "1CA9588A-E3EB-44FC-9515-6EB89BB8C1D6",
"versionEndExcluding": "14.1-73.37",
"versionStartIncluding": "14.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"matchCriteriaId": "046FF602-D956-4961-89BF-2041A3590004",
"versionEndIncluding": "14.1-73.37",
"versionStartIncluding": "14.1-66.68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3286D2C3-EA7E-4D9C-95DE-05D462DC8B1B",
"versionEndExcluding": "13.1-64.23",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C77243A7-1FDB-4557-88BE-EDF3BAA56A81",
"versionEndExcluding": "14.1-73.37",
"versionStartIncluding": "14.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]