Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
HTTP Request Smuggling (CWE-444) represents a critical vulnerability affecting Citrix NetScaler ADC and Gateway products through inconsistent interpretation of HTTP requests. When multiple HTTP parsers (proxies, load balancers, backend servers) interpret request boundaries differently, attackers can inject malicious requests that bypass security controls, authentication, and WAF protections. This vulnerability is particularly severe because it affects gateway and load-balancing infrastructure—devices trusted to protect internal networks. Organizations running vulnerable versions (ADC before 14.1-73.37 or 13.1-64.23; Gateway before 14.1-73.37 FIPS or 13.1-64.23) face direct exposure to request smuggling attacks that could lead to privilege escalation, session hijacking, or lateral movement within protected networks.
While no specific MITRE ATT&CK techniques are currently mapped to this CVE, Casky's 754 security skills—powered by Claude AI with extended reasoning—would detect HTTP Request Smuggling attack patterns by analyzing proxy behavior anomalies, request header manipulation, and boundary condition detection across network traffic. Practitioners using Casky would observe findings highlighting suspicious request fragmentation, conflicting Content-Length and Transfer-Encoding headers, and discrepancies between how frontend and backend systems parse incoming HTTP traffic. The platform's skill library would flag techniques associated with defense evasion and credential access (T1036, T1110) that typically accompany smuggling attacks, enabling security teams to identify exploitation attempts before attackers establish persistence or move laterally through compromised gateways.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-88773. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation