
PEACH
Un cadre d’isolation des locataires
CVE-2026-88774 is a security feature bypass vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway caused by improper HTTP URL-based expression usage. It affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability was published on September 27, 2026, with patches made available the same day. It carries a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Citrix Advisory).
The vulnerability stems from improper handling of HTTP URL-based expressions used in feature policy evaluation within NetScaler ADC and Gateway. An unauthenticated, network-based attacker can craft specific HTTP requests that exploit this improper expression evaluation to bypass configured feature policies. No CWE classification has been formally assigned, but the root cause aligns with improper input validation or expression handling in policy enforcement logic. Attack requirements indicate that specific deployment or execution conditions must be present (AT:P), meaning exploitation is not universally trivial but requires no privileges or user interaction (GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to bypass security feature policies configured on NetScaler ADC or Gateway appliances. The direct impact on the vulnerable system is limited (low confidentiality and integrity impact), but the subsequent system impact is rated high for both confidentiality and integrity, indicating that downstream systems or resources protected by the bypassed policies may be significantly exposed. This could allow attackers to access resources or perform actions that should have been blocked by the NetScaler policy engine, potentially enabling lateral movement into protected network segments or applications (GitHub Advisory, Citrix Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation for CVE-2026-88774 specifically (Feedly). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability was disclosed alongside a broader set of NetScaler CVEs (CVE-2026-88771 through CVE-2026-88778), some of which involve RCE and have been reported as actively exploited zero-days, which may elevate overall attacker interest in this vulnerability family (CISA Alert, The Hacker News).
Citrix has released patched versions addressing CVE-2026-88774. Administrators should upgrade to the following fixed versions as soon as possible:
After patching, administrators should review and validate all configured feature policies to confirm they are functioning as intended. No specific configuration-based workaround has been published (Citrix Advisory, GitHub Advisory).
The disclosure of CVE-2026-88774 occurred alongside several higher-severity NetScaler CVEs, including RCE zero-days (CVE-2026-88771, CVE-2026-88772), which drew significant attention from the security community. CISA issued an alert regarding critical zero-day vulnerabilities in NetScaler ADC and Gateway, and national CERTs including CERT-EU, Ireland's NCSC, and Canada's CCCS published advisories covering the broader vulnerability set (CISA Alert, CERT-EU, NCSC Ireland). Security media outlets including The Hacker News, CyberSecurityNews, and Heise covered the broader NetScaler vulnerability cluster, with community discussion on Infosec.Exchange and X highlighting the risk to internet-facing NetScaler deployments (The Hacker News, CyberSecurityNews).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."