SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-88773

CRITICAL · CVSS 10 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

Citrix NetScaler ADC and Gateway products are vulnerable to HTTP request/response smuggling due to inconsistent handling of HTTP requests, potentially allowing attackers to bypass security controls, intercept sensitive data, or execute unauthorized actions. Organizations using affected versions prior to the specified updates should prioritize patching to mitigate the risk of exploitation, given the critical severity rating of 9.3. This vulnerability poses a significant threat to network security and data integrity, making it essential for affected users to act swiftly.

CVE
CVE-2026-88773
Severity
CRITICAL
CVSS
10
EPSS
0.36%
Citrix

Original NVD Description

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

Related CVEs

Other vulnerabilities affecting the same vendor(s)