Threat Intelligence

Critical Citrix NetScaler Flaw Lets Attackers Run Malicious Code Without Logging In

The Hacker News · 30 Sept 2026
Key Takeaway If your business uses Citrix NetScaler ADC or Gateway, apply the latest security patches immediately and check for signs of compromise, as this flaw is already being actively exploited.

Security researchers have published technical details of CVE-2026-88772, a critical vulnerability in Citrix NetScaler ADC and Gateway devices that is already being exploited in the wild. The flaw, rated 9.5 out of 10 in severity, is a memory overflow bug in how NetScaler handles the DTLS network protocol, and CISA has warned it could allow remote code execution or cause devices to crash.

According to researchers at watchTowr, the problem stems from a mismatch in how NetScaler processes handshake data during a DTLS connection. By sending specially crafted network packets that misreport their own size, an attacker can trick the device into writing far more data into memory than the buffer is designed to hold. Once enough malicious packets are sent, the excess data overflows the buffer, and researchers found this can be exploited to run arbitrary malicious code with the highest level of system privileges, all without needing to log in first.

Because NetScaler devices sit at the edge of business networks handling remote access and application delivery, a compromise can give attackers a foothold into the wider network. This vulnerability has already been patched by Citrix, and given active exploitation, unpatched devices remain at serious risk.

Primary source cisa.gov ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.