CVE-2026-88772: a DTLS memory overflow in Citrix NetScaler ADC and Gateway is being exploited now
Citrix published security bulletin CTX697096 on 27 September 2026 covering eight vulnerabilities in
NetScaler ADC and NetScaler Gateway. Three of them carry the critical label, and two are confirmed as
exploited in the wild: CVE-2026-88771 and CVE-2026-88772. Both were used against real appliances before
the vendor made patches available, which is the detail that separates this round of NetScaler fixes from
the steady stream of routine gateway advisories.
Vulnerability overview
CVE-2026-88772 is a memory overflow in NetScaler ADC and NetScaler Gateway rated 9.5 under CVSS v4 by
Citrix. A successful attack leads to remote code execution or, depending on how the overflow resolves, a
denial of service. The exploitation precondition is narrow on paper and wide in practice: DTLS must be
enabled. Citrix states that DTLS is enabled by default on a VPN virtual server, so an appliance that
terminates remote-access VPN traffic usually satisfies the condition without any administrator having
chosen it deliberately.
The related CVE-2026-88771 is the other exploited flaw, scoring 9.5 as well. It stems from insufficient
input validation and lets an unauthenticated remote attacker execute arbitrary commands. Citrix and the
national CERTs state that all NetScaler ADC and NetScaler Gateway deployments are affected by that
weakness and that no extra functionality or configuration is required to exploit it. Together the two
vulnerabilities give an attacker a path that does not need credentials and does not depend on an unusual
setup.
The remaining six issues are serious without being remotely triggerable in a default configuration:
CVE-2026-88773 (HTTP request smuggling, 9.3, needs HTTP enabled), CVE-2026-88774 (feature policy bypass
through HTTP URL-based policy expressions, 7.0, only when such expressions exist), CVE-2026-88775
(memory overflow, 8.8, Gateway, SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA virtual server), CVE-2026-88776
(memory overflow, 8.8, requires an Oracle-type load-balancing virtual server), CVE-2026-88777 (memory
overflow, 8.8, requires a load-balancing, content-switching or CGNAT LSN/NAT64 configuration with a
non-HTTP Layer 7 protocol), and CVE-2026-88778 (predictable TCP initial sequence numbers, 8.8, needs TCP
enabled).
Mechanism and exploitation conditions
What is publicly documented for CVE-2026-88772 is deliberately thin, and that matters when planning
defences. The advisories describe a memory overflow reachable over DTLS that ends in remote code
execution or denial of service. They do not publish the vulnerable function, the malformed message
structure, or a proof-of-concept. Treating the gap as unknown is more useful than guessing at it: the
part that is known, and known to be sufficient, is that DTLS must be reachable and the build must be
older than the fixed versions.
Two conditions therefore decide whether a given appliance is at risk. The build has to predate the fixed
release for its branch, and DTLS has to be enabled on a VPN virtual server or reachable in some other
way. Since DTLS is on by default at a VPN virtual server, the second condition is often already met. That
combination is why the effective exposure of this flaw is broader than the "requires DTLS" phrasing
suggests at first reading.
The exploitation timeline adds a second consideration. Both CVE-2026-88771 and CVE-2026-88772 were
exploited before patches existed, which means the usual patch-then-monitor order is not enough. An
appliance that has been internet-reachable and unpatched since the disclosure needs evidence-based
handling rather than an assumption of cleanliness.
Impact
NetScaler ADC and Gateway sit at the edge of the network. They terminate VPN sessions, publish internal
web applications, and broker authentication for systems behind them. Code execution on that device
hands an attacker a position with visibility into the traffic it handles and, depending on the
configuration, a foothold to move inward. The denial-of-service outcome is not a soft failure either: a
VPN concentrator that stops responding takes remote access down with it for everyone who depends on it.
Attackers in this position can read credentials in transit, modify the content they broker, and reach
back-end services that trust the gateway's network position. The published indicators of compromise,
distributed through the NetScaler console, give defenders a starting point, but absence of an alert is
not proof of absence.
Affected products and scope
The vulnerable branches are NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.37, NetScaler ADC
and NetScaler Gateway 13.1 before 13.1-64.23, NetScaler ADC FIPS before 14.1-73.37 FIPS, and NetScaler ADC
FIPS and NDcPP before 13.1-37.279. Secure Private Access hybrid deployments that rely on NetScaler
instances share the exposure. The advisory covers customer-managed appliances; Citrix-managed cloud
services and Citrix Managed Adaptive Authentication are updated by Cloud Software Group. CERT-FR notes
that, without the fixes, all appliances are vulnerable in their default configuration.
Exposure context
A ZoomEye probe of app="Citrix NetScaler" matched 239,201 internet-facing assets. The CVE-indexed filter vul.cve="CVE-2026-88772" returned zero at the time of the query, which is expected for a disclosure this recent and says nothing about real-world exposure. Product-fingerprint counts describe devices that match the Citrix NetScaler fingerprint; they are not a count of confirmed-vulnerable instances.
Remediation and mitigations
Apply the fixed builds listed by Citrix and repeated in the national advisories:
| Branch | Fixed version |
| --- | --- |
| NetScaler ADC and Gateway 14.1 | 14.1-73.37 and later |
| NetScaler ADC and Gateway 13.1 | 13.1-64.23 and later |
| NetScaler ADC FIPS | 14.1-73.37 FIPS and later |
| NetScaler ADC FIPS and NDcPP | 13.1-37.279 and later |
Because exploitation of CVE-2026-88771 and CVE-2026-88772 was observed before fixes existed, NCSC-NL
advises treating any appliance that was reachable while unpatched as potentially compromised. Preserve
relevant logs and a memory dump before installing the update, review them afterwards, and check the
indicators of compromise Citrix published through the NetScaler console. Installing the update stops
further exploitation; it does not by itself rule out an earlier intrusion. Deployments that use
Secure Private Access in a hybrid design with NetScaler instances fall inside the same advisory scope.
Organisations that rely on Citrix-managed cloud services are covered by Cloud Software Group rather than
by this bulletin.
References
- NCSC-NL advisory NCSC-2026-0394: https://advisories.ncsc.nl/2026/ncsc-2026-0394.html
- CERT-FR alert CERTFR-2026-ALE-011: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2026-ALE-011/
- CERT-FR advisory CERTFR-2026-AVI-1235: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- Citrix bulletin CTX697096: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Top comments (0)