Skip to content
Critical RCE Vulnerability in Citrix NetScaler Exploited via DTLS Memory Overflow

Critical RCE Vulnerability in Citrix NetScaler Exploited via DTLS Memory Overflow

First seen 28 Sep 2026, 12:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 13:05 UTC
  • •CVE-2026-88772 allows RCE and DoS on Citrix NetScaler ADC/Gateway appliances.
  • •Active exploitation confirmed; first public PoC released on September 28, 2026.
  • •Patching is critical; affected versions include ADC/Gateway 14.1 < 14.1-73.37 and 13.1 < 13.1-64.23.

A critical vulnerability, CVE-2026-88772, affecting Citrix NetScaler ADC and Gateway appliances has been disclosed, allowing unauthenticated remote code execution (RCE) and denial-of-service (DoS) through a DTLS memory overflow. The vulnerability is present in versions 14.1 prior to 14.1-73.37 and 13.1 prior to 13.1-64.23, with active exploitation confirmed. The first public proof-of-concept (PoC) was released on September 28, 2026, following the vulnerability's addition to the CISA KEV catalog on September 27, 2026. Attackers can exploit this flaw by sending crafted DTLS packets to vulnerable VPN virtual servers, which are enabled by default. Users are advised to apply patches or disable DTLS on affected systems immediately. The CVSS score for this vulnerability is 9.5, indicating a critical severity level. Citrix has published a mitigation advisory (CTX697096) detailing the necessary patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-27
CVE-2026-88771 and CVE-2026-88772 published
Citrix disclosed two critical vulnerabilities, including CVE-2026-88772, with active exploitation reported.
Sploitus
2026-09-27
CVE-2026-88771 and CVE-2026-88772 added to CISA KEV
CISA included both vulnerabilities in its Known Exploited Vulnerabilities catalog due to active exploitation.
Sploitus
2026-09-28
First public PoC released
A proof-of-concept for CVE-2026-88772 was made publicly available, demonstrating the exploit's capabilities.
Sploitus

More articles in this cluster (2)

Following this threat?

Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed