Site icon VMVirtualMachine.com

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

By The Hacker News
Publication Date: 2026-09-30 05:30:00

Ravie LakshmananSep 30, 2026Vulnerability / Network Security

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that’s rooted in the NetScaler Packet Processing Engine (NSPPE).

“Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.

The issue, per watchTowr, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header’s fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete…

Exit mobile version