{"id":"CVE-2026-88773","published":"2026-09-27T17:16:56.507","lastModified":"2026-09-29T16:17:13.370","description":"Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","cwes":["CWE-444"],"vendors":["citrix"],"products":["netscaler application delivery controller","netscaler gateway"],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows for inconsistent interpretation of HTTP requests, leading to potential HTTP Request/Response smuggling attacks, which can be exploited to manipulate network traffic and potentially execute unauthorized actions.","exploitability":"Exploitation is moderately difficult as it requires precise manipulation of HTTP requests, and the attacker must have network access to the affected Citrix NetScaler ADC or Gateway.","blast_radius":"If exploited, this could lead to significant network disruptions and unauthorized access to services, impacting the integrity and availability of network traffic.","remediation":"Upgrade to Citrix NetScaler ADC versions 14.1-73.37 or later, 13.1-64.23 or later, and Citrix NetScaler Gateway versions 14.1-73.37 FIPS or later, 13.1-64.23 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["http-request-smuggling","network-traffic","citrix","adc","gateway"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:45:22.488Z"}}