CVE-2026-88774: 
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-88774 is a security feature bypass vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway caused by improper HTTP URL-based expression usage. It affects NetScaler ADC versions before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; and NetScaler Gateway versions before 14.1-73.37 and before 13.1-64.23. The vulnerability was published on September 27, 2026, with patches made available the same day. It carries a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Citrix Advisory).

Technical details

The vulnerability stems from improper handling of HTTP URL-based expressions used in feature policy evaluation within NetScaler ADC and Gateway. An unauthenticated, network-based attacker can craft specific HTTP requests that exploit this improper expression evaluation to bypass configured feature policies. No CWE classification has been formally assigned, but the root cause aligns with improper input validation or expression handling in policy enforcement logic. Attack requirements indicate that specific deployment or execution conditions must be present (AT:P), meaning exploitation is not universally trivial but requires no privileges or user interaction (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to bypass security feature policies configured on NetScaler ADC or Gateway appliances. The direct impact on the vulnerable system is limited (low confidentiality and integrity impact), but the subsequent system impact is rated high for both confidentiality and integrity, indicating that downstream systems or resources protected by the bypassed policies may be significantly exposed. This could allow attackers to access resources or perform actions that should have been blocked by the NetScaler policy engine, potentially enabling lateral movement into protected network segments or applications (GitHub Advisory, Citrix Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation for CVE-2026-88774 specifically (Feedly). The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability was disclosed alongside a broader set of NetScaler CVEs (CVE-2026-88771 through CVE-2026-88778), some of which involve RCE and have been reported as actively exploited zero-days, which may elevate overall attacker interest in this vulnerability family (CISA Alert, The Hacker News).

Mitigation and workarounds

Citrix has released patched versions addressing CVE-2026-88774. Administrators should upgrade to the following fixed versions as soon as possible:

  • NetScaler ADC: 14.1-73.37 or later; 13.1-64.23 or later; 14.1-73.37 FIPS or later; 13.1.37.279 FIPS and NDcPP or later
  • NetScaler Gateway: 14.1-73.37 or later; 13.1-64.23 or later

After patching, administrators should review and validate all configured feature policies to confirm they are functioning as intended. No specific configuration-based workaround has been published (Citrix Advisory, GitHub Advisory).

Community reactions

The disclosure of CVE-2026-88774 occurred alongside several higher-severity NetScaler CVEs, including RCE zero-days (CVE-2026-88771, CVE-2026-88772), which drew significant attention from the security community. CISA issued an alert regarding critical zero-day vulnerabilities in NetScaler ADC and Gateway, and national CERTs including CERT-EU, Ireland's NCSC, and Canada's CCCS published advisories covering the broader vulnerability set (CISA Alert, CERT-EU, NCSC Ireland). Security media outlets including The Hacker News, CyberSecurityNews, and Heise covered the broader NetScaler vulnerability cluster, with community discussion on Infosec.Exchange and X highlighting the risk to internet-facing NetScaler deployments (The Hacker News, CyberSecurityNews).

Additional resources


Source: This report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88778HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88777HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88776HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88775HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88774HIGH7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management