AI analysis
CVE-2026-88774 is a feature-policy bypass in Citrix NetScaler ADC and Citrix NetScaler Gateway caused by improper use of HTTP URL-based expressions. A remote, unauthenticated attacker who can satisfy the required preconditions can send crafted HTTP requests that evade policies intended to control access. Impact on the appliance itself is limited to low confidentiality and integrity, with no availability impact, but the same bypass can have high confidentiality and integrity consequences for protected downstream systems (CVSS 4.0 base score 7.0, high). Affected products are NetScaler ADC before 14.1-73.37 and before 13.1-64.23, including the listed FIPS and NDcPP builds, and NetScaler Gateway before 14.1-73.37 and before 13.1-64.23, typically used as enterprise edge load balancers or remote-access gateways. No public proof-of-concept is known and the issue is not in CISA KEV; a related headline about actively exploited NetScaler remote-code-execution flaws does not match this policy-bypass description and is not confirmation that this CVE is being exploited.
What to do: Upgrade NetScaler ADC to 14.1-73.37 or later or to 13.1-64.23 or later, FIPS builds to 14.1-73.37 FIPS or later, and FIPS/NDcPP builds to 13.1.37.279 or later; upgrade NetScaler Gateway to 14.1-73.37 or later or to 13.1-64.23 or later. Prioritize internet-facing appliances, then review HTTP URL-based feature policies and access logs for requests that reached resources those policies should have blocked.
Affected
| Citrix NetScaler ADC | before 14.1-73.37; before 13.1-64.23; before 14.1-73.37 FIPS; before 13.1.37.279 FIPS and NDcPP |
| Citrix NetScaler Gateway | before 14.1-73.37; before 13.1-64.23 |
Estimated exposure
large≈10,000–100,000 internet-exposed appliances — Estimate from typical public internet-scan counts of exposed Citrix NetScaler ADC and Gateway appliances, which are commonly deployed as enterprise load balancers and remote-access gateways; total installed base including internal-only…
Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.