IT

Tracker / CVE-2026-88773

CVE-2026-88773

Critical 10.0

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

Affected products and versions

citrix netscaler_application_delivery_controller · 13.1 → 13.1-64.23
citrix netscaler_application_delivery_controller · 13.1 → 13.1.37.279
citrix netscaler_application_delivery_controller · 14.1 → 14.1-73.37
citrix netscaler_application_delivery_controller · 14.1-66.68 → 14.1-73.37
citrix netscaler_gateway · 13.1 → 13.1-64.23
citrix netscaler_gateway · 14.1 → 14.1-73.37

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References