CVE-2026-88772
NetScaler ADC/Gateway memory overflow leading to remote code execution or denial of service when DTLS is enabled (CVSS 9.5, CISA KEV, exploited as a zero-day)
- Severity
- critical
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway all versions before the fix
- Fixed in
- Citrix NetScaler ADC/Gateway 14.1-73.37
- Detection basis
- Appliance fingerprint
- Shipped rule
- Citrix NetScaler ADC/Gateway: NetScaler ADC/Gateway memory overflow leading to remote code execution or denial of service when DTLS is enabled (CVSS 9.5, CISA KEV, exploited as a zero-day)
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-09-28
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-28, same Citrix bulletin and same fix builds as CVE-2026-88771 above. The second of the two exploited zero-days. DTLS is the DEFAULT for VPN virtual servers, so the precondition holds on a stock Gateway; the fingerprint cannot tell Gateway from ADC-only, so the precondition stays in the title rather than gating the row (same stance as CVE-2026-8452). No `epss` - unrated by FIRST on the day, not zero. Version-gate wall as CVE-2026-88771.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →Review the measured benchmark, then use the verified remediation process.