DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-88773: CVE-2026-88773: Critical HTTP Request Smuggling in Citrix NetScaler ADC and Gateway

CVE-2026-88773: Critical HTTP Request Smuggling in Citrix NetScaler ADC and Gateway

Vulnerability ID: CVE-2026-88773
CVSS Score: 10.0
Published: 2026-09-27

A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.

TL;DR

Unauthenticated HTTP request smuggling in Citrix NetScaler allows session hijacking, policy bypass, and cache poisoning due to boundary parsing differences.


Technical Details

  • CWE ID: CWE-444
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 10.0 (Critical)
  • CVSS v4.0 Score: 9.3 (Critical)
  • Exploit Status: None/Theoretical (No public PoC code)
  • CISA KEV Status: Not Listed (Related CVEs CVE-2026-88771/2 are listed)
  • Primary Impact: Session Hijacking, Security Bypass, Cache Poisoning

Affected Systems

  • Citrix NetScaler ADC (Standard/Enterprise/Platinum)
  • Citrix NetScaler Gateway
  • Citrix NetScaler ADC FIPS
  • Citrix NetScaler ADC NDcPP

Mitigation Strategies

  • Upgrade firmware to the latest secure version (14.1-73.37 / 13.1-64.24 or later)
  • Disable TCP multiplexing and keep-alive settings on downstream web servers to prevent socket reuse
  • Configure Web Application Firewalls (WAF) to detect and block contradictory Content-Length and Transfer-Encoding headers
  • Enable Enhanced ISN Generation to mitigate related TCP prediction attacks

Remediation Steps:

  1. Identify vulnerable NetScaler appliances and execute configuration checks for active HTTP/SSL virtual servers.
  2. Download the appropriate secure firmware build (14.1-73.37 or 13.1-64.24) from the official Citrix portal.
  3. Apply the firmware update to both standalone nodes or in high-availability (HA) pairs sequentially.
  4. Execute CLI commands on all partitions to enable Enhanced ISN Generation: 'set ns tcpparam -enhancedISNgeneration ENABLED'.
  5. Save the active configuration locally via 'save ns config -all' and reboot the appliance if required.

Read the full report for CVE-2026-88773 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)