Feature Policy Bypass in Citrix NetScaler ADC and Gateway Affects Multiple Versions
CVE-2026-88774

7HIGH

Key Information:

Vendor
CVE Published:
27 September 2026

What is CVE-2026-88774?

A vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway allows attackers to bypass feature policies due to improper configuration in HTTP URL-based expressions. This affects multiple versions of both products, leading to potential unauthorized access or manipulation of system functionality. Organizations utilizing these Citrix products should apply the necessary patches to mitigate this security risk.

Affected Version(s)

ADC 0 < 14.1-73.37

ADC 0 < 13.1-64.23

ADC 0 < 14.1-73.37 FIPS

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.