CVE-2026-88774 in Citrix NetScaler: policy bypass via URL expressions
NCSC-NL detailed CVE-2026-88774, rated 7.0, affecting Citrix NetScaler ADC and Gateway: incorrect use of HTTP URL-based policy expressions lets attackers bypass a feature policy. Only appliances with such expressions configured are affected; the fix is in Citrix bulletin CTX697096, covering eight vulnerabilities, two of them actively exploited.
- CVE-2026-88774 is rated 7.0 and affects Citrix NetScaler ADC and Gateway
- Only appliances with configured HTTP URL-based policy expressions are vulnerable
- Patch CTX697096 fixes eight vulnerabilities, two actively exploited
- Admins should inventory expressions with owners and review dates
Read next
Security