Critical severityNVD Advisory· Published Sep 27, 2026
CVE-2026-88773
CVE-2026-88773
Description
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Affected products
2- Range: <14.1-73.37, <13.1-64.23, <14.1-73.37 FIPS, <13.1-37.279, <13.1-37.279 NDcPP
- Range: <14.1-73.37 FIPS, <13.1-64.23
Patches
Vulnerability mechanics
References
1News mentions
1- Citrix Confirms NetScaler 0-Day RCE Vulnerabilities Actively Exploited in AttackCyber Security News · Sep 27, 2026