chiprook
← Security
SecurityOctober 1, 2026, 10:20

CVE-2026-88774 in Citrix NetScaler: policy bypass via URL expressions

NCSC-NL detailed CVE-2026-88774, rated 7.0, affecting Citrix NetScaler ADC and Gateway: incorrect use of HTTP URL-based policy expressions lets attackers bypass a feature policy. Only appliances with such expressions configured are affected; the fix is in Citrix bulletin CTX697096, covering eight vulnerabilities, two of them actively exploited.

CVE-2026-88774 in Citrix NetScaler: policy bypass via URL expressions
#Citrix#NetScaler
Read next
Security

CVE-2026-19490: NetScaler SAML Bypass Detection and Mitigation

Security

ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass

Security

CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE

Security

Exploit details for Citrix NetScaler CVE-2026-88772 reveal pre-auth shellcode path