• PATCH AVAILABLE

CVE-2026-88773: pre-auth request smuggling in Citrix ADC

Remote attackers can abuse an HTTP request/response smuggling flaw to interact with Citrix ADC and Gateway in a way that can violate confidentiality and integrity; this is tracked as CVE-2026-88773. The issue affects Citrix ADC and Gateway builds before the fixed releases (for example ADC 14.x before 14.1-73.37 and ADC 13.x before 13.1-64.23 and related FIPS/NDcPP builds). An attacker needs only network access to a vulnerable ADC/Gateway instance and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.00361
CWE
CWE-444
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth, remotely reachable parsing bug in an internet-facing product and fixed builds are available (see vendor fixed releases), so prioritize patching exposed ADC/Gateway appliances or otherwise block access immediately.

What is CVE-2026-88773?

Remote attackers can abuse an HTTP request/response smuggling flaw to interact with Citrix ADC and Gateway in a way that can violate confidentiality and integrity; this is tracked as CVE-2026-88773. The issue affects Citrix ADC and Gateway builds before the fixed releases (for example ADC 14.x before 14.1-73.37 and ADC 13.x before 13.1-64.23 and related FIPS/NDcPP builds). An attacker needs only network access to a vulnerable ADC/Gateway instance and does not require valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Citrix ADC are affected?

BRANCHAFFECTEDFIXED
ADC 14.xbefore 14.1-73.3714.1-73.37
ADC 13.xbefore 13.1-64.2313.1-64.23
ADC 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
ADC 13.xbefore 13.1-37.279 and NDcPP13.1-37.279 and NDcPP
Gateway 14.xbefore 14.1-73.37 FIPS14.1-73.37 FIPS
Gateway 13.xbefore 13.1-64.2313.1-64.23

Is CVE-2026-88773 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-88773

  1. Apply vendor fixes: upgrade ADC/Gateway to the fixed builds such as 14.1-73.37 or 13.1-64.23 (and corresponding FIPS/NDcPP fixes).
  2. If you cannot immediately patch, restrict network exposure of ADC/Gateway management and service interfaces to trusted networks only.
  3. Follow Citrix guidance and release notes for any configuration changes or additional mitigations.
  4. Monitor ADC/Gateway logs for unusual request parsing errors and signs of HTTP request smuggling attempts.

Frequently asked questions

Is CVE-2026-88773 being actively exploited?

There are no public reports of active exploitation of CVE-2026-88773 as of 2026-09-29.

Which Citrix ADC and Gateway versions are affected by CVE-2026-88773?

Citrix ADC and Gateway releases prior to the fixed builds are affected, for example ADC 14.x before 14.1-73.37 and ADC 13.x before 13.1-64.23, including the noted FIPS and NDcPP variants.

Is there a patch for CVE-2026-88773?

Yes. Citrix published fixed builds such as 14.1-73.37 and 13.1-64.23 (and corresponding FIPS/NDcPP fixes); upgrade to those releases.

Does CVE-2026-88773 require authentication?

No. The vulnerability can be exploited without authentication against network-accessible Citrix ADC or Gateway instances.

References