Vulnerabilities · 1 day ago

Citrix NetScaler DTLS Bug Hits VPN Gateways

watchTowr Labs identified CVE-2026-88772 in Citrix NetScaler ADC and NetScaler Gateway, and Citrix says the flaw has been exploited in the wild; CISA’s federal remediation deadline lands on 2026-09-30. The issue affects the appliance’s internet-facing access path, not a side feature.

The bug is in DTLS, the encrypted UDP path NetScaler uses for VPN virtual servers by default unless an admin has turned it off. A carefully shaped packet can trigger a memory overflow before any login happens, so the trusted remote-access channel itself is what trips the failure.

That puts the exposure on the gateway layer that fronts remote access and application traffic. For operators running VPN or front-door delivery on affected branches, the immediate problem is not just the fix itself but getting the upgrade through a safe maintenance and rollback window without cutting off access.

CVE-2026-88772

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Sep 30

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-10-01

Editions

Related stories