PatchSiren cyber security CVE debrief
CVE-2026-88774 Citrix NetScaler CVE debrief
A vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway could allow an attacker to bypass feature policies due to improper HTTP URL-based expression usage. This issue affects ADC versions before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP; and Gateway versions before 14.1-73.37 and 13.1-64.23. The vulnerability could lead to feature policy bypass, requiring defenders to verify affected versions, apply patches, and monitor for potential security incidents.
- Vendor
- Citrix NetScaler
- Product
- ADC
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-27
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-27
Who should care
Citrix NetScaler ADC and Gateway administrators, security teams, and IT professionals responsible for configuring and maintaining these systems should assess exposure and prioritize patching.
Why it matters
CVE-2026-88774 vulnerability in Citrix NetScaler ADC and Gateway could lead to feature policy bypass, requiring defenders to verify affected versions, apply patches, and monitor for potential security incidents.
- Verify configurations for vulnerable HTTP URL-based expressions to prevent feature policy bypass
- Assess exposure of affected Citrix NetScaler ADC and Gateway versions
- Prioritize patching for affected versions to prevent potential security risks
- Monitor for potential feature policy bypass attempts to detect possible security incidents
Technical summary
The vulnerability in Citrix NetScaler ADC and Gateway is due to improper HTTP URL-based expression usage, leading to a feature policy bypass. Affected versions include ADC before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1.37.279 FIPS and NDcPP; and Gateway before 14.1-73.37 and 13.1-64.23. Citrix NetScaler ADC and Gateway administrators should assess exposure and verify if their configurations are vulnerable to feature policy bypass. Defenders should prioritize verifying affected versions and applying vendor patches.
Defensive priority
Defenders should prioritize verifying affected versions and applying vendor patches. Citrix NetScaler ADC and Gateway administrators should assess exposure and verify if their configurations are vulnerable to feature policy bypass.
Recommended defensive actions
- Verify affected versions of Citrix NetScaler ADC and Gateway
- Apply vendor patches for affected versions
- Review configurations for vulnerable HTTP URL-based expressions
- Monitor for potential feature policy bypass attempts
- Assess exposure of affected Citrix NetScaler ADC and Gateway versions
- Prioritize patching for affected versions to prevent potential security risks
- Verify configurations for vulnerable HTTP URL-based expressions to prevent feature policy bypass
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation or impact is limited. Further verification is required to determine the full scope of affected systems and potential consequences.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88774 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88774
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88774 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88774
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.