Critical Citrix NetScaler Flaw Exploited for Remote Code Execution
A high-severity vulnerability in Citrix NetScaler ADC and Gateway is being actively exploited. Organizations are urged to apply patches immediately to prevent unauthorized access.
TL;DR
- CVE-2026-88772 is a pre-authentication memory overflow flaw in Citrix NetScaler DTLS handling.
- Exploitation can lead to remote shellcode execution without authentication.
- The vulnerability has a CVSS score of 9.5, indicating critical severity.
- Active exploitation is occurring in the wild; patching is urgent.
- Organizations using NetScaler ADC or Gateway should update immediately.
Cybersecurity researchers have revealed exploit details for a critical flaw in Citrix NetScaler ADC and Gateway appliances. Tracked as CVE-2026-88772, the vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems.
With a CVSS score of 9.5, this memory overflow issue in the DTLS protocol handling poses a significant risk to organizations relying on these network infrastructure components. Evidence suggests the flaw is already being exploited in real-world attacks.
Technical Breakdown of CVE-2026-88772
- The flaw resides in the Datagram Transport Layer Security (DTLS) implementation within NetScaler.
- It manifests as a memory overflow condition that can be triggered before authentication.
- Successful exploitation grants attackers the ability to execute shellcode remotely.
- No user interaction or prior authentication is required to exploit the vulnerability.
Impact and Recommended Actions
- Organizations using Citrix NetScaler ADC or Gateway are at immediate risk.
- Attackers can gain full control of affected devices, potentially leading to lateral movement.
- Citrix has released patches; applying them is the highest priority mitigation step.
- Until patched, consider isolating NetScaler instances from untrusted networks.
- Monitor logs for unusual DTLS traffic patterns that may indicate exploitation attempts.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.