Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-88774 is a feature policy bypass vulnerability affecting Citrix NetScaler ADC and Gateway appliances through versions 14.1-73.37 and 13.1-64.23. The vulnerability stems from improper handling of HTTP URL-based expressions, allowing attackers to circumvent configured security policies that should restrict access to protected resources. This is particularly critical because NetScaler appliances serve as primary access control points for many organizations—sitting between users and internal applications. A successful exploit could allow unauthorized access to sensitive data, internal services, or administrative functions, making this a high-severity issue (CVSS 7.2) despite not yet being actively exploited in the wild.
While Casky.ai currently has zero mapped skills specifically indexed to this CVE, the underlying attack pattern aligns with policy enforcement bypass techniques that practitioners should monitor through behavioral analysis. Organizations using Casky would benefit from developing custom detection logic around HTTP request manipulation and expression evaluation anomalies—looking for suspicious URL patterns in access logs that attempt to bypass rewrite rules or policy expressions. Security teams should prioritize updating affected NetScaler instances to patched versions (14.1-73.37 or later, 13.1-64.23 or later) and implement compensating controls such as enhanced HTTP request validation at the WAF or proxy layer. As the threat landscape evolves and exploitation techniques emerge, Casky's skill library will expand to map detection patterns to relevant MITRE ATT&CK techniques, likely under categories such as T1190 (Exploit Public-Facing Application) or T1562 (Impair Defenses).
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-88774. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation