security1 publisher
Attackers are exploiting a NetScaler DTLS memory overflow before authentication
Citrix patched CVE-2026-88772, a pre-authentication DTLS memory overflow in NetScaler that attackers are already exploiting as a zero-day. DTLS ships enabled on VPN virtual servers, so a Gateway is exposed unless it was deliberately disabled.
Publishers:labs.watchtowr.com
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence58