Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
A memory buffer overflow in the DTLS protocol handler of Citrix NetScaler ADC and NetScaler Gateway allows an unauthenticated remote attacker to achieve remote code execution or cause a denial of service. The flaw is present in the 13.1 and 14.1 release lines of both products before specific patch boundaries. Because DTLS is enabled by default on VPN virtual servers, most internet-facing NetScaler Gateway deployments are exposed without any additional configuration.
CWE-119 describes a class of memory safety failures where software reads or writes data outside the bounds of an allocated buffer. In NetScaler ADC and Gateway, the DTLS protocol handler fails to properly constrain operations on memory buffers when processing incoming DTLS packets. DTLS is a datagram-based variant of TLS used for VPN and remote-access traffic, and its stateful parsing logic must handle variable-length fields from untrusted network sources. When that parsing logic does not enforce buffer boundaries, attacker-supplied packet content can corrupt adjacent memory regions, producing conditions that range from process crashes to controlled code execution.
An unauthenticated attacker sends crafted DTLS packets to the NetScaler DTLS listener. The malformed packets trigger the out-of-bounds memory operation in the handler, which can corrupt process memory in ways that either crash the appliance (denial of service) or, with sufficient control over memory layout, redirect execution to attacker-supplied code. No credentials or prior session state are required. The precondition is that DTLS must be enabled on the target virtual server, a condition that holds by default on VPN virtual servers, making the majority of internet-facing NetScaler Gateway deployments reachable without any additional setup by the attacker.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Citrix NetScaler runs inside your authorization boundary, CVE-2026-88772 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of September 30, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.
Knox does not patch Citrix NetScaler on your behalf. Remediation is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that support your documentation posture ahead of your next assessment. The fix belongs to your team; maintaining a compliant posture while you apply it is not something you have to manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including cases like CVE-2026-88772. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team the opportunity to act before findings accumulate.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-88772 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding and documenting the remediation is what keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








