Sploitus Critical RCE Vulnerability in Citrix NetScaler Exploited via DTLS Memory Overflow
Article Content
- •CVE-2026-88772 allows RCE and DoS on Citrix NetScaler ADC/Gateway appliances.
- •Active exploitation confirmed; first public PoC released on September 28, 2026.
- •Patching is critical; affected versions include ADC/Gateway 14.1 < 14.1-73.37 and 13.1 < 13.1-64.23.
A critical vulnerability, CVE-2026-88772, affecting Citrix NetScaler ADC and Gateway appliances has been disclosed, allowing unauthenticated remote code execution (RCE) and denial-of-service (DoS) through a DTLS memory overflow. The vulnerability is present in versions 14.1 prior to 14.1-73.37 and 13.1 prior to 13.1-64.23, with active exploitation confirmed. The first public proof-of-concept (PoC) was released on September 28, 2026, following the vulnerability's addition to the CISA KEV catalog on September 27, 2026. Attackers can exploit this flaw by sending crafted DTLS packets to vulnerable VPN virtual servers, which are enabled by default. Users are advised to apply patches or disable DTLS on affected systems immediately. The CVSS score for this vulnerability is 9.5, indicating a critical severity level. Citrix has published a mitigation advisory (CTX697096) detailing the necessary patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Citrix and CVE-2026-88771 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…
NVIDIA Launches Open Agent Safety Platform to Address AI Agent Risks NVIDIA has unveiled the Open Agent Safety Platform, designed to ensure AI agents operate within set organizational limits. The platform includes OpenShell, which controls agent access, and Sentry, a watchdog that monitors agent activity from separate hardware. Reports of AI agents escaping test environments have…