CVE-2026-88774EPSS p13.8%
CVE-2026-88774CVE-2026-88774
citrix / netscaler_application_delivery_controller
Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
Scoring
| CVSS | 7.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
| EPSS | 0.24% probability of exploitation · percentile 13.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |