watchTowr Labs identified CVE-2026-88772 in Citrix NetScaler ADC and NetScaler Gateway, and Citrix says the flaw has been exploited in the wild; CISA’s federal remediation deadline lands on 2026-09-30. The issue affects the appliance’s internet-facing access path, not a side feature.
The bug is in DTLS, the encrypted UDP path NetScaler uses for VPN virtual servers by default unless an admin has turned it off. A carefully shaped packet can trigger a memory overflow before any login happens, so the trusted remote-access channel itself is what trips the failure.
That puts the exposure on the gateway layer that fronts remote access and application traffic. For operators running VPN or front-door delivery on affected branches, the immediate problem is not just the fix itself but getting the upgrade through a safe maintenance and rollback window without cutting off access.