CVE-2026-88773

Published: Set 27, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,3
Source: 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
CRITICAL 10,0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Non-Repudiation Access Control
Potential Impacts:
Unexpected State Hide Activities Bypass Protection Mechanism
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
Application

Netscaler Application Delivery Controller by Citrix

Version Range Affected
From 14.1-66.68 (inclusive)
To 14.1-73.37 (inclusive)
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netscaler Application Delivery Controller by Citrix

Version Range Affected
From 14.1 (inclusive)
To 14.1-73.37 (exclusive)
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netscaler Application Delivery Controller by Citrix

Version Range Affected
From 13.1 (inclusive)
To 13.1.37.279 (exclusive)
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netscaler Gateway by Citrix

Version Range Affected
From 13.1 (inclusive)
To 13.1-64.23 (exclusive)
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netscaler Application Delivery Controller by Citrix

Version Range Affected
From 13.1 (inclusive)
To 13.1-64.23 (exclusive)
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netscaler Gateway by Citrix

Version Range Affected
From 14.1 (inclusive)
To 14.1-73.37 (exclusive)
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Netscaler Application Delivery Controller by Citrix

Version Range Affected
From 13.1 (inclusive)
To 13.1.37.279 (exclusive)
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096