Critical request smuggling flaw found in Citrix NetScaler
Citrix NetScaler ADC and Gateway contain an HTTP request smuggling vulnerability tracked as CVE-2026-88773 with a CVSS score of 9.3. Exploitation requires HTTP enabled and no authentication; CVE-2026-88771 and CVE-2026-88772 in the same CTX697096 update are being actively exploited.
- CVE-2026-88773 in NetScaler ADC and Gateway scores CVSS 9.3
- Exploitation needs HTTP enabled and no authentication
- CTX697096 patches cover 14.1, 13.1, FIPS and NDcPP builds
- NCSC-NL advises saving logs and a memory dump before patching
Read next
Security