CVE-2026-88773
NetScaler ADC/Gateway HTTP request smuggling through inconsistent request interpretation (CVSS 9.3)
- Severity
- critical
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway all versions before the fix
- Fixed in
- Citrix NetScaler ADC/Gateway 14.1-73.37
- Detection basis
- Appliance fingerprint
- Shipped rule
- Citrix NetScaler ADC/Gateway: NetScaler ADC/Gateway HTTP request smuggling through inconsistent request interpretation (CVSS 9.3)
- Added to NewScan
- 2026-09-28
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-28, same bulletin and fix builds as the two KEV rows above; NOT on KEV and not observed exploited. Depends on specific configurations, which the fingerprint cannot see. Carried so the id reaches the published /cve index for the assessor keying remediation off the bulletin - the advisory observation itself lists KEV rows first and will not surface this one while any KEV row is unconfirmed (appliance_tools: `kev = [...] or unconfirmed`), which is the intended priority.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →Review the measured benchmark, then use the verified remediation process.