← Back to search

CVE-2026-88773

10 CRITICAL

Published 2026-09-27 · Updated 2026-09-28

AI risk analysis

Summary
This vulnerability allows for inconsistent interpretation of HTTP requests, leading to potential HTTP Request/Response smuggling attacks, which can be exploited to manipulate network traffic and potentially execute unauthorized actions.
Exploitability
Exploitation is moderately difficult as it requires precise manipulation of HTTP requests, and the attacker must have network access to the affected Citrix NetScaler ADC or Gateway.
Blast radius
If exploited, this could lead to significant network disruptions and unauthorized access to services, impacting the integrity and availability of network traffic.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Citrix NetScaler ADC versions 14.1-73.37 or later, 13.1-64.23 or later, and Citrix NetScaler Gateway versions 14.1-73.37 FIPS or later, 13.1-64.23 or later.
http-request-smugglingnetwork-trafficcitrixadcgateway

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses

CWE-444

Vendors

citrix

Products

netscaler application delivery controller, netscaler gateway

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.