Junglewise Threat Intelligence

CVE-2026-88773: Citrix NetScaler ADC HTTP Request/Response smuggling

CVE-2026-88773 · Severity: info · Published 2026-09-27

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway. Vendors: Citrix.

Executive brief

Citrix NetScaler ADC and Gateway are application delivery controllers that sit between clients and backend servers, processing and optimizing HTTP traffic. An HTTP request smuggling vulnerability could allow an attacker to inject malicious requests that bypass security controls or cause requests to be routed to unintended backends, potentially leading to cache poisoning, session hijacking, or unauthorized access to sensitive data.

Technical details

This HTTP Request/Response smuggling vulnerability arises from inconsistent interpretation of HTTP requests in NetScaler ADC and Gateway. An attacker with network access can craft specially-formed HTTP requests that are parsed differently by the proxy and backend server, allowing request desynchronization. The vulnerability affects multiple versions before specified patch levels and can be exploited to bypass security policies or access restricted resources.

Affected products

  • Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 NDcPP
  • Citrix NetScaler Gateway before 14.1-73.37 FIPS and before 13.1-64.23

Timeline

  • 2026-09-27: disclosed

References

Related threats