Overview
Citrix's September 27, 2026 security bulletin CTX697096 is best known for the two actively-exploited NetScaler remote code execution zero-days it confirmed, CVE-2026-88771 and CVE-2026-88772. Bundled into the same bulletin, however, is CVE-2026-88773, a separate and independently critical flaw: an "inconsistent interpretation of HTTP requests" issue — more commonly known as HTTP request/response smuggling (CWE-444) — affecting Citrix NetScaler ADC and NetScaler Gateway.
Unlike the two zero-days, Citrix states CVE-2026-88773 was found internally, and as of publication it is not listed as actively exploited in the wild. That does not lower its ceiling: a CVSS v4.0 base score of 9.3 (Critical) reflects that a successful desync attack against a NetScaler appliance sitting in front of load-balanced, content-switched, VPN, or authentication virtual servers can let an attacker smuggle a hidden request or response past the proxy — with downstream effects ranging from cache poisoning to authentication bypass. Given that ADC and Gateway commonly terminate HTTP/SSL traffic for exactly those virtual server types, the precondition for exposure is common, not exotic.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-88773 |
| Severity | Critical |
| CVSS Score | 9.3 (CVSS v4.0) — AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N |
| Attack Vector | Network — crafted HTTP requests sent to a NetScaler-fronted virtual server |
| Authentication | None required |
| Privileges Required | None |
| User Interaction | None |
| Impact | Integrity of subsequent HTTP requests/responses (high) — request/response desync enabling cache poisoning, access-control bypass, and cross-request data leakage |
Precondition: Citrix notes exposure requires a Load Balancing, Content Switching, VPN, or Authentication virtual server of type HTTP or SSL configured on the appliance — the standard configuration for the vast majority of production ADC and Gateway deployments.
Discovery & exploitation status: Citrix credits internal discovery for CVE-2026-88773. It is not included in Citrix's list of actively-exploited flaws from this bulletin (that distinction belongs solely to CVE-2026-88771 and CVE-2026-88772), and as of this writing it does not appear in CISA's Known Exploited Vulnerabilities (KEV) catalog. Public technical write-ups specific to CVE-2026-88773's exact smuggling primitive (e.g., which header or chunked-encoding ambiguity is abused) had not surfaced at publication — treat the mechanics below as a description of the HTTP smuggling class as it applies to NetScaler's proxy role, not a confirmed exploit recipe.
How It Works
HTTP request smuggling exploits disagreements between two or more HTTP devices in a chain — here, the NetScaler appliance acting as reverse proxy/load balancer, and the backend application server it forwards traffic to — over where one HTTP request ends and the next begins.
The classic root causes are:
- Conflicting
Content-LengthandTransfer-Encodingheaders (CL.TE / TE.CL desync) — the front-end and back-end disagree on which header governs body length. - Malformed or duplicate
Transfer-Encoding: chunkedframing that one parser accepts and another rejects or truncates differently. - Inconsistent handling of obscure whitespace, header folding, or non-standard delimiters that one HTTP parser normalizes and another does not.
Citrix's own description — "inconsistent interpretation of HTTP requests" — places CVE-2026-88773 squarely in this category. In a reverse-proxy architecture like NetScaler's, an attacker who can get the appliance and the backend server to disagree about request boundaries can smuggle a second, hidden request inside what the front end perceives as a single request body. Because NetScaler reuses persistent backend connections to serve multiple client requests, that smuggled request can be interpreted as belonging to a different, subsequent client — letting the attacker:
- Poison the response cache so other users receive attacker-controlled content.
- Hijack another user's request, potentially capturing session tokens, authentication headers, or response bodies intended for someone else.
- Bypass front-end access controls (e.g., a load balancer or WAF-style routing rule) by hiding a request the appliance would otherwise inspect or reject inside a request it allows.
Because the flaw requires no authentication and no user interaction — it is purely a matter of sending crafted, well-formed-looking HTTP traffic to a NetScaler-fronted virtual server — the barrier to attempting exploitation is low, even without public exploit details.
Impact Assessment
Who Is At Risk
Any organization running NetScaler ADC or NetScaler Gateway with an HTTP or SSL-type Load Balancing, Content Switching, VPN, or Authentication virtual server configured — which describes most production NetScaler deployments, since these are the core reverse-proxy and remote-access functions the product exists to provide.
Potential Attack Chains
- Desync injection — Attacker sends a specially malformed HTTP request to a NetScaler-fronted virtual server, exploiting a parsing disagreement between NetScaler and the backend.
- Request/response hijacking — The smuggled request or response is attributed to a different, legitimate client sharing the same backend connection.
- Session and credential exposure — If the hijacked exchange carries authentication cookies, bearer tokens, or SSO artifacts (particularly relevant on Gateway/VPN and Authentication virtual servers), the attacker gains a path toward account takeover.
- Cache poisoning at scale — Where response caching sits behind the proxy, a single successful smuggling request can persist attacker-controlled content for many subsequent, unrelated visitors.
- Control bypass — Security logic that trusts NetScaler's interpretation of a request boundary (rate limiting, WAF rules, access policies) can be sidestepped if the backend sees a different boundary than the appliance enforced.
Mitigation
Immediate Actions
- Upgrade to a fixed build: NetScaler ADC/Gateway 14.1-73.37 or later, 13.1-64.23 or later, 14.1-FIPS 14.1-73.37 or later, or 13.1-FIPS/13.1-NDcPP 13.1.37.279 or later. These are the same fixed builds Citrix shipped for the actively-exploited CVE-2026-88771/88772 zero-days in the same bulletin — one upgrade cycle addresses all eight CTX697096 CVEs.
- Do not assume an August-era patch is sufficient. Builds that only addressed the earlier CVE-2026-19490 authentication-bypass issue, or even the initial September fix for CVE-2026-88771/88772, predate this bulletin's final builds — confirm the exact build number against the fixed-version list above.
- Inventory every NetScaler ADC/Gateway instance and its exact build, and prioritize appliances with internet-facing Gateway/VPN or Authentication virtual servers.
Detection Opportunities
Request smuggling is notoriously difficult to spot in standard access logs because each device only sees its own interpretation of the traffic. Focus on:
- Backend web server logs showing HTTP requests that don't correspond to any request NetScaler's own logs recorded as separate.
- Anomalous or unexpected responses served to users who did not request that content (a hallmark of cache poisoning or response hijacking).
- Malformed or ambiguous
Transfer-Encoding/Content-Lengthcombinations in raw packet captures at the NetScaler ingress. - Unexplained authentication or session anomalies — one user's session data appearing in another user's session.
Defence-in-Depth
- Disable HTTP keep-alive reuse for untrusted-to-backend segments where feasible, or enforce strict, single-parser HTTP normalization at the edge.
- Terminate and re-normalize HTTP strictly at the proxy layer rather than passing ambiguous framing through unmodified.
- Where compensating controls exist, prefer HTTP/2 to backend servers that support it, since HTTP/2's binary framing removes the ambiguity that enables classic CL.TE/TE.CL smuggling (note: this is a general defensive pattern, not a Citrix-confirmed workaround for this specific CVE).
- Keep WAF/IPS signatures current for HTTP smuggling patterns, and treat any NetScaler-fronted authentication flow as a high-value target for monitoring.
Background
CVE-2026-88773 was disclosed as one of eight CVEs in Citrix Security Bulletin CTX697096 (September 27, 2026), alongside the actively-exploited zero-days CVE-2026-88771 (unauthenticated RCE, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE/DoS, CVSS 9.5) — see CosmicBytez Labs' coverage of those two exploited flaws for the active-exploitation angle. The remaining bulletin entries (CVE-2026-88774 through CVE-2026-88778) cover a WAF-evading URL policy bypass and several memory-overflow denial-of-service issues.
CVE-2026-88773 is distinct from those zero-days in one important respect: Citrix found it internally, and there is no public evidence of in-the-wild exploitation at this time. It should not be deprioritized on that basis. This is the second major NetScaler bulletin in roughly six weeks (following August's CVE-2026-19490 authentication-bypass disclosure), reinforcing NetScaler ADC/Gateway as a persistent, high-value target for both defenders and attackers — and organizations patching for the confirmed zero-days in this same bulletin should treat CVE-2026-88773 as covered by the same upgrade, not as a lower-priority follow-up.