CVE-2026-88774

HIGH

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

CVSS v3.1 Score

7.2
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Complexity
LOW
Privileges
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE
Published: 9/27/2026Modified: 9/29/2026

Related Intelligence (5)

CRITICALZero Day

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Overview On September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772 . Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor

CVE-2026-88771CVE-2026-88772
Rapid7
CRITICALZero Day

NetScaler admins told to patch critical zero-days in ADC and Gateway now

Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “ Monday will be too late ,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirme

CVE-2026-88771CVE-2026-88772
CSO Online
MEDIUMVulnerability

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778

[object Object]

CVE-2026-88771CVE-2026-88772
r/blueteamsec
HIGHVulnerability

NVD HIGH: CVE-2026-88774 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue ...

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.

CVE-2026-88774
NIST NVD
CRITICALZero Day

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

<p>CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: <a href="https://www.cve.org/CVERecord?id=CVE-2026-88771">CVE-2026-88771</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88772">CVE-2026-88772</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-88773">CVE-2026-88773</a>, <a href="https://www.cve.

CVE-2026-88771CVE-2026-88772
CISA Advisories

References (1)