Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2026-88772
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to a memory overflow in DTLS-enabled virtual servers when processing DTLS traffic. A remote attacker can send crafted input to execute arbitrary code or cause a denial of service.
DTLS must be enabled; it is enabled by default on VPN virtual servers.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2026-88772
Citrix NetScaler Gateway - addressed in versions 13.1-64.23, 14.1-73.37
External References
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- https://support.citrix.com/support-home/topic-article-list?trendingCategory=20&trendingTopicName=Security%20Bulletin
- https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/