Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
Published: 2026-09-27
Score: 7 High
EPSS: n/a
KEV: No
Impact: Feature Policy Bypass
Action: Patch ASAP
AI Analysis

Impact

Citrix NetScaler ADC and Gateway contain a flaw that undermines feature policy controls by incorrectly evaluating HTTP URL based expressions. The result is a bypass of intended policy restrictions, enabling an attacker to use functionality that would normally be blocked. The vulnerability does not explicitly state changes to confidentiality or integrity, but it compromises the integrity of the policy enforcement mechanism.

Affected Systems

The affected releases are Citrix NetScaler ADC versions before 14.1‑73.37, before 13.1‑64.23, and the corresponding FIPS and NDcPP builds, as well as Citrix NetScaler Gateway versions prior to 14.1‑73.37 and 13.1‑64.23. All these releases are vulnerable to the feature policy bypass.

Risk and Exploitability

The CVSS score of 7.0 indicates high severity, but the EPSS score is not available, so the likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog. An attacker could trigger the flaw by sending specially crafted HTTP requests that exploit the improper handling of URL based expressions. The attack vector is inferred from the description since explicit details are not provided.

Generated by OpenCVE AI on September 27, 2026 at 17:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Citrix NetScaler ADC and Gateway firmware updates that provide the fix for CVE‑2026‑88774.
  • If an update cannot be deployed immediately, temporarily disable or remove the feature-policy expressions that rely on URL based evaluations.
  • Enhance input validation for URL based expressions or enforce stricter policy checks to prevent improper evaluation.
  • Enable detailed logging for feature‑policy requests and monitor logs for anomalous traffic patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on September 27, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Sun, 27 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
Title Feature policy bypass due to improper HTTP URL based expression usage
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-09-27T16:14:02.993Z

Reserved: 2026-09-10T07:14:57.369Z

Link: CVE-2026-88774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:56.633

Modified: 2026-09-27T17:16:56.633

Link: CVE-2026-88774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T18:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control