CVE-2026-88773

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

CVSS
9.3
EPSS
—
CISA KEV
Not listed
Exploitation
No report
Public exploits
None seen
State
PUBLISHED

Coverage

What we observed

No signals recorded

CVE® is a registered trademark of The MITRE Corporation. CVE Records are reproduced under the CVE Program Terms of Use. CVE Program Terms of Use