CVE-2026-88773: HTTP Request Smuggling
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Affected Citrix NetScaler ADC releases are those before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 NDcPP. Affected Citrix NetScaler Gateway releases are before 14.1-73.37 FIPS and 13.1-64.23.
How can I determine whether my appliance is affected?
Identify whether the appliance is running ADC or Gateway, including whether it is a FIPS or NDcPP deployment, then compare its installed release with the applicable fixed-version boundary. Any listed product release earlier than its corresponding boundary is affected.