AI analysis
CVE-2026-88773 is a critical HTTP request/response smuggling flaw (CWE-444) in Citrix NetScaler ADC and Citrix NetScaler Gateway, caused by inconsistent interpretation of HTTP requests. A remote attacker can send a crafted request over the network with no privileges and no user interaction so the appliance and a downstream component disagree on where one request ends and the next begins. CVSS 4.0 scores this 9.3, with high integrity impact on the vulnerable system and high confidentiality and integrity impact on subsequent systems, and no availability impact; the CVE record does not describe remote code execution. It affects ADC builds before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP, and Gateway builds before 14.1-73.37 FIPS and before 13.1-64.23. No public proof of concept is known and the CVE is not in CISA KEV; a related headline about actively exploited NetScaler RCE issues is not identified as this smuggling flaw.
What to do: Upgrade NetScaler ADC to 14.1-73.37 or later, 13.1-64.23 or later, 14.1-73.37 FIPS or later, or 13.1-37.279 NDcPP or later, and NetScaler Gateway to 14.1-73.37 FIPS or later or 13.1-64.23 or later, prioritizing internet-facing appliances. After patching, review HTTP and security logs for anomalous or desynchronized requests and invalidate sessions that may have been poisoned. No public exploit is known and this CVE is not in CISA KEV, but unauthenticated network access makes prompt patching appropriate.
Affected
| Citrix NetScaler ADC | before 14.1-73.37; before 13.1-64.23; before 14.1-73.37 FIPS; before 13.1-37.279 and NDcPP |
| Citrix NetScaler Gateway | before 14.1-73.37 FIPS; before 13.1-64.23 |
Estimated exposure
largeon the order of tens of thousands of internet-exposed appliances (roughly 10,000–100,000), fronting many more enterprise users — Order-of-magnitude estimate from historical public internet-scan counts of exposed Citrix NetScaler ADC and Gateway appliances, which commonly fall in the tens of thousands; not a census of builds vulnerable to this CVE.
Description
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.