Critical Citrix NetScaler Flaw Lets Attackers Run Malicious Code Without Logging In
Security researchers have published technical details of CVE-2026-88772, a critical vulnerability in Citrix NetScaler ADC and Gateway devices that is already being exploited in the wild. The flaw, rated 9.5 out of 10 in severity, is a memory overflow bug in how NetScaler handles the DTLS network protocol, and CISA has warned it could allow remote code execution or cause devices to crash.
According to researchers at watchTowr, the problem stems from a mismatch in how NetScaler processes handshake data during a DTLS connection. By sending specially crafted network packets that misreport their own size, an attacker can trick the device into writing far more data into memory than the buffer is designed to hold. Once enough malicious packets are sent, the excess data overflows the buffer, and researchers found this can be exploited to run arbitrary malicious code with the highest level of system privileges, all without needing to log in first.
Because NetScaler devices sit at the edge of business networks handling remote access and application delivery, a compromise can give attackers a foothold into the wider network. This vulnerability has already been patched by Citrix, and given active exploitation, unpatched devices remain at serious risk.