🔴 CVE-2026-88772

CVE-2026-88772 is a critical memory overflow vulnerability (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to achieve Remote Code Execution or Denial of Service without any user interaction. The vulnerability is triggered via the DTLS protocol, which is enabled by default on VPN virtual servers, meaning a large proportion of internet-facing deployments are exposed out-of-the-box. CISA has confirmed active exploitation in the wild and added this CVE to its Known Exploited Vulnerabilities catalog.

← Back to Overview
HIGH_RISK
Risk Level
9.5
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-27

Added to CISA KEV: 2026-09-27 0 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-27)

Summary

CVE-2026-88772 is a critical memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway when Datagram Transport Layer Security (DTLS) is enabled. It is significant because it allows unauthenticated, remote attackers to achieve remote code execution (RCE) or trigger a denial-of-service (DoS) condition on vulnerable appliances [2][3]. Given that DTLS is enabled by default for VPN virtual servers, many NetScaler Gateway deployments are exposed to this vulnerability by default [2].

Exploitation

  • Active Exploitation: The vulnerability is being actively exploited in the wild, and CISA has added it to its Known Exploited Vulnerabilities (KEV) Catalog [1].
  • Threat Actors: Specific threat actors or ransomware campaigns have not been publicly identified by name, but reports confirm global exploitation is underway [1].
  • Exploit Tools: Public availability of proof-of-concept code or specific exploit tools has not been confirmed in the initial advisory, though the fact of active exploitation confirms the existence of functional exploits [1].
  • Attack Prerequisites: This is a remote, network-based attack. No authentication is required for exploitation, and no specific user interaction is needed [2].

Affected Products & Patches

  • Affected Versions: Citrix NetScaler ADC and Citrix NetScaler Gateway versions prior to 14.1-73.37 [4][5].
  • Patch Availability: Fixed releases (14.1-73.37 and later) are available, and vendors strongly urge all affected customers to upgrade immediately [4].
  • Mitigations: For those unable to patch immediately, disabling DTLS on affected appliances serves as an effective temporary mitigation, as the vulnerability requires DTLS to be enabled [2].

Impact

  • Successful Exploitation: Provides an attacker the ability to execute arbitrary code with the privileges of the affected service (RCE) or force the appliance to crash, resulting in a denial-of-service (DoS) [2].
  • Business Risk: Internet-facing deployments are at extreme risk. Compromise of a NetScaler ADC or Gateway often grants attackers a foothold into the internal network, potentially facilitating lateral movement, data exfiltration, or the disruption of critical remote access services for the entire organization [1].

Sources

  1. Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC ...

    CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively…

  2. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days ...

    "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed," the company said. It did not say ... CVE-2026-88772 (CVSS v4 score: 9.5) - A memory overflow that can lead to remote code execution or denial-of-service (DoS). It affects appliances with DTLS ena…

  3. Article Record Type: Security Bulletin

    CVE-2026-88772, Memory overflow vulnerability leading to Remote Code Execution or Denial of Service, DTLS configuration enabled on NetScaler ADC ...

  4. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for ...

    Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed. Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible. Citrix NetScaler ADC and Citrix NetScaler…

  5. CVE Record: CVE-2026-88772

    Description. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, ...