Utility for remote code execution (RCE) and denial-of-service (DoS) against Citrix NetScaler ADC and Gateway appliances. Leverages the DTLS memory overflow vulnerability (CWE-119) to achieve unauthenticated remote code execution when DTLS is enabled on VPN virtual servers.
- NetScaler ADC/Gateway 14.1 < 14.1-73.37
- NetScaler ADC/Gateway 13.1 < 13.1-64.23
- FIPS/NDcPP variants prior to 14.1-73.37 FIPS and 13.1.37.279
- All unpatched builds prior to CTX697096 patches (published Sep 2026)
Improper restriction of operations within the bounds of a memory buffer (CWE-119) in the DTLS record handling routine on UDP/443. Allows arbitrary memory write leading to RCE or DoS when a malformed DTLS packet is processed.
python poc.py -u --mode check
python poc.py -u --mode exploit
python poc.py --list targets.txt --mode exploit -j 12
.
- Detects NetScaler ADC/Gateway via HTTP paths & build strings
- Sends crafted DTLS ClientHello with overflow payload (no kit)
- Triggers remote code execution or service DoS on unpatched appliances
- Full unauthenticated RCE on exposed VPN portals
- Works against in-the-wild exploited builds
- Stealthy – mimics legitimate DTLS traffic
Authorized testing and incident response only. Do not crash production appliances.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
