← Back to CVE intelligence
CVE intelligence

CVE-2026-88773

Citrix NetScaler HTTP request smuggling

Published Sep 27, 2026Sources checked Sep 27, 2026
9.3CRITICALCVSS out of 10
What this means

Review the available evidence

CVE-2026-88773 and is rated Critical severity with a CVSS score of 9.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

Public exploit: Not collected. Upgrade to the fixed build for your branch: 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 FIPS/NDcPP, or a later release listed by Citrix.

CISA KEVNot listedBased on the latest collected catalog
EPSSUnavailableNo current score collected
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-88773?

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.