Knox CVE Database
/
CVE-2026-88772
High
8.1

CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

Added to the CISA KEV catalog:
September 27, 2026

Overview

A memory buffer overflow in the DTLS protocol handler of Citrix NetScaler ADC and NetScaler Gateway allows an unauthenticated remote attacker to achieve remote code execution or cause a denial of service. The flaw is present in the 13.1 and 14.1 release lines of both products before specific patch boundaries. Because DTLS is enabled by default on VPN virtual servers, most internet-facing NetScaler Gateway deployments are exposed without any additional configuration.

Vulnerability details

Affected vendor
Citrix
Affected product
NetScaler
Weakness type (CWE)
CWE-119

CWE-119 describes a class of memory safety failures where software reads or writes data outside the bounds of an allocated buffer. In NetScaler ADC and Gateway, the DTLS protocol handler fails to properly constrain operations on memory buffers when processing incoming DTLS packets. DTLS is a datagram-based variant of TLS used for VPN and remote-access traffic, and its stateful parsing logic must handle variable-length fields from untrusted network sources. When that parsing logic does not enforce buffer boundaries, attacker-supplied packet content can corrupt adjacent memory regions, producing conditions that range from process crashes to controlled code execution.


An unauthenticated attacker sends crafted DTLS packets to the NetScaler DTLS listener. The malformed packets trigger the out-of-bounds memory operation in the handler, which can corrupt process memory in ways that either crash the appliance (denial of service) or, with sufficient control over memory layout, redirect execution to attacker-supplied code. No credentials or prior session state are required. The precondition is that DTLS must be enabled on the target virtual server, a condition that holds by default on VPN virtual servers, making the majority of internet-facing NetScaler Gateway deployments reachable without any additional setup by the attacker.

Severity and impact

8.1
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor NetScaler syslog and ns.log for unexpected process crashes, core dumps, or restarts of NetScaler processes, which may indicate memory corruption triggered by malformed DTLS input rather than routine failures.
  • Look for high volumes of DTLS connection attempts from a single source IP or from IPs with no prior authentication history against the VPN virtual server, particularly where sessions terminate abnormally without completing a handshake.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 30, 2026

Additional hardening

  • Upgrade NetScaler ADC and NetScaler Gateway 14.1 to build 14.1-73.37 or later, and 13.1 to build 13.1-64.23 or later (FIPS and NDcPP variants: 14.1-73.37 FIPS and 13.1-37.279 respectively); see References for the vendor advisory covering all boundaries.
  • If immediate patching is not possible, disable DTLS on VPN virtual servers where it is not operationally required, removing the attack surface without affecting non-DTLS remote-access methods.
  • Restrict DTLS traffic at the network perimeter to known, authorized source IP ranges, reducing exposure to unauthenticated external attackers who would otherwise reach the listener directly.
  • Follow the Citrix forensic triage guidance referenced in the vendor advisory to assess whether appliances that were exposed and unpatched show signs of memory corruption or unexpected process behavior prior to upgrade.

Key dates

Published (NVD)
September 27, 2026
Added to CISA KEV
September 27, 2026
Remediation deadline
September 30, 2026
Last updated
September 28, 2026

References

Frequently asked questions

Does CVE-2026-88772 affect my FedRAMP authorization?

If Citrix NetScaler runs inside your authorization boundary, CVE-2026-88772 is a direct concern for your Federal Risk and Authorization Management Program (FedRAMP) authorization. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of September 30, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-88772?

Knox does not patch Citrix NetScaler on your behalf. Remediation is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that support your documentation posture ahead of your next assessment. The fix belongs to your team; maintaining a compliant posture while you apply it is not something you have to manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including cases like CVE-2026-88772. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team the opportunity to act before findings accumulate.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-88772 isn't remediated by September 30, 2026?

An unremediated CVE-2026-88772 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding and documenting the remediation is what keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.