SEPTEMBER 30, 2026
Live Feed
Back to database
Case File

CVE-2026-88774

HIGH · CVSS 7.2 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-09-30

CyberRota Analysis

AI-Generated

Citrix NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23 are vulnerable to a feature policy bypass caused by improper handling of HTTP URL expressions. This flaw could allow unauthorized access to sensitive features, potentially compromising the security posture of affected systems. Organizations using these Citrix products should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-88774
Severity
HIGH
CVSS
7.2
EPSS
0.24%
Citrix

Original NVD Description

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

Related CVEs

Other vulnerabilities affecting the same vendor(s)