← Back to blog

Critical Citrix NetScaler Flaw Exploited for Remote Code Execution

A high-severity vulnerability in Citrix NetScaler ADC and Gateway is being actively exploited. Organizations are urged to apply patches immediately to prevent unauthorized access.

TL;DR

  • CVE-2026-88772 is a pre-authentication memory overflow flaw in Citrix NetScaler DTLS handling.
  • Exploitation can lead to remote shellcode execution without authentication.
  • The vulnerability has a CVSS score of 9.5, indicating critical severity.
  • Active exploitation is occurring in the wild; patching is urgent.
  • Organizations using NetScaler ADC or Gateway should update immediately.

Cybersecurity researchers have revealed exploit details for a critical flaw in Citrix NetScaler ADC and Gateway appliances. Tracked as CVE-2026-88772, the vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems.

With a CVSS score of 9.5, this memory overflow issue in the DTLS protocol handling poses a significant risk to organizations relying on these network infrastructure components. Evidence suggests the flaw is already being exploited in real-world attacks.

Technical Breakdown of CVE-2026-88772

  • The flaw resides in the Datagram Transport Layer Security (DTLS) implementation within NetScaler.
  • It manifests as a memory overflow condition that can be triggered before authentication.
  • Successful exploitation grants attackers the ability to execute shellcode remotely.
  • No user interaction or prior authentication is required to exploit the vulnerability.

Impact and Recommended Actions

  • Organizations using Citrix NetScaler ADC or Gateway are at immediate risk.
  • Attackers can gain full control of affected devices, potentially leading to lateral movement.
  • Citrix has released patches; applying them is the highest priority mitigation step.
  • Until patched, consider isolating NetScaler instances from untrusted networks.
  • Monitor logs for unusual DTLS traffic patterns that may indicate exploitation attempts.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.