Skip to content

Security1 publisher2 min readPublished

Attackers are exploiting a NetScaler DTLS memory overflow before authentication

Citrix patched CVE-2026-88772, a pre-authentication DTLS memory overflow in NetScaler that attackers are already exploiting as a zero-day. DTLS ships enabled on VPN virtual servers, so a Gateway is exposed unless it was deliberately disabled.

The Watch · Security desk

Illustration accompanying Attackers are exploiting a NetScaler DTLS memory overflow before authentication

What happened

  • watchTowr Labs says two of the fixed bugs, not one, were already being exploited in the wild when Citrix shipped the advisory.
  • CVE-2026-88772 is one of eight vulnerabilities Citrix fixed in a single bulletin, CTX697096, released Sunday.
  • Citrix's fixed builds are NetScaler ADC and Gateway 14.1-73.37 and 13.1-64.23 and later.
  • Separate FIPS and NDcPP builds are fixed at 14.1-73.37 FIPS and 13.1-37.279 and later.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Exploitation ran before the fix existed, so a patched appliance can still be holding an intruder who got in before the update.
  • decision Operators pick between installing the fixed build and turning DTLS off; because the flaw needs DTLS enabled, -dtls OFF closes it without an upgrade window.
  • precedent Two actively exploited zero-days in one NetScaler bulletin point to sustained targeting, so a Gateway needs incident review after patching, not just the update.

The exposed surface is DTLS reassembly. DTLS is TLS carried over UDP, and one UDP packet can hold several DTLS records, each opening with a 13-byte header [10]. A record carrying handshake data adds a 12-byte fragment header [11]. Four of its fields matter: length, message_seq, fragment_offset and fragment_length [12]. length is the full message size, fragment_offset says where a fragment belongs, and fragment_length how many bytes it carries [12]. A message can arrive split across many fragments, and the server rebuilds it by placing each fragment at the offset it claims [12]. NetScaler holds the received bytes in linked buffers it calls NSBs, and once reassembly finishes an NSPPE function stitches that chain together [13].

NetScaler is Citrix's application delivery controller, now under Cloud Software Group, and it sits in front of an organization's applications to balance load and terminate SSL/TLS [1]. NetScaler Gateway adds the VPN and remote access that make it internet-facing [2]. A security appliance concentrates a defensive function at a single chokepoint every connection has to pass through [15]. Citrix calls such a box hardened, meaning minimal services, a restricted shell, a controlled update path and security-tuned defaults, and pitches it as tougher to break into than a general-purpose server [14]. That reassembly runs before the sender authenticates [3], so anyone who can reach the box with UDP packets reaches the flaw [10].

watchTowr Labs, not Citrix, wrote the technical walk-through and titled it "Here We Go Again," its second analysis of this one advisory in two days [16].

What to watch

  • Whether a public exploit or proof-of-concept for CVE-2026-88772 appears.
  • The identity of the second exploited bug in CTX697096 and whether it also needs no login.
  • Any Citrix or CISA figure for how many NetScaler boxes were hit.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories