CVE-2026-88774
Feature policy bypass due to improper HTTP URL based expression usage
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
| Vendor | citrix netscaler |
| Product | adc |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for citrix netscaler adc
Be the first to know when new unknown vulnerabilities affecting citrix netscaler adc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Citrix NetScaler / ADC
0 < 14.1-73.37 0 < 13.1-64.23 0 < 14.1-73.37 FIPS 0 < 13.1.37.279 FIPS and NDcPP
Citrix NetScaler / Gateway
0 < 14.1-73.37 0 < 13.1-64.23