Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-88774",
"assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
"assignerShortName": "NetScaler",
"dateUpdated": "2026-09-27T16:14:02.993Z",
"dateReserved": "2026-09-10T07:14:57.369Z",
"datePublished": "2026-09-27T16:14:02.993Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
"shortName": "NetScaler",
"dateUpdated": "2026-09-27T16:14:02.993Z"
},
"title": "Feature policy bypass due to improper HTTP URL based expression usage",
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.<p>This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a f<span>eature policy bypass due to improper HTTP URL based expression usage.</span></p>"
}
]
}
],
"affected": [
{
"vendor": "Citrix NetScaler",
"product": "ADC",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "patch",
"lessThan": "14.1-73.37"
},
{
"version": "0",
"status": "affected",
"versionType": "patch",
"lessThan": "13.1-64.23"
},
{
"version": "0",
"status": "affected",
"versionType": "patch",
"lessThan": "14.1-73.37 FIPS"
},
{
"version": "0",
"status": "affected",
"versionType": "patch",
"lessThan": "13.1.37.279 FIPS and NDcPP"
}
]
},
{
"vendor": "Citrix NetScaler",
"product": "Gateway",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "patch",
"lessThan": "14.1-73.37"
},
{
"version": "0",
"status": "affected",
"versionType": "patch",
"lessThan": "13.1-64.23"
}
]
}
],
"references": [
{
"url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
]
}
}
}