Critical Pre‑Auth RCE in Citrix NetScaler ADC & Gateway (CVE‑2026‑88772)
What It Is — A memory‑overflow flaw in the DTLS handling code of Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to inject shellcode and achieve remote code execution. The vulnerability is tracked as CVE‑2026‑88772 with a CVSS 9.5 rating.
Exploitability — Publicly disclosed proof‑of‑concept exploits are circulating; researchers confirm active exploitation in the wild.
Affected Products — Citrix NetScaler ADC (all supported versions prior to the September 2026 patch) and Citrix Gateway.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuous vulnerability‑management program that can surface critical flaws before attackers do.
- Timely patching and documented remediation provide defensible evidence for auditors and enterprise buyers demanding a trustworthy security posture.
- Monitoring for anomalous DTLS traffic creates an audit trail that supports incident‑response readiness and control‑objective verification.
Recommended Actions
- Deploy the Citrix‑issued September 2026 patch immediately and verify the installed version.
- Update your vulnerability‑management workflow to include DTLS‑related components and ensure rapid risk scoring for high‑severity CVSS ≥ 9.0 findings.
- Enable detailed DTLS logging, ingest the logs into a SIEM, and set alerts for unexpected handshake failures or payload anomalies.
Source: The Hacker News – Citrix NetScaler CVE‑2026‑88772 Exploit Details