DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

DKCISSP News DeskThe Hacker News30 Sept 2026, 11:00 am
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).

the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said .

This parsing inconsistency can be exploited by an attacker to craft a malicious record that makes the record look small, while the actual data being copied to the buffer is much larger in size, resulting in an overflow.

After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data." watchTowr's analysis further found that this overflow can be weaponized to divert control flow to arbitrary shellcode with root-level privileges by using the mprotect() system call to defeat NX (no-execute) protections.

The disclosure comes a day after the preemptive exposure management company released a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.

Once every position has arrived, the server considers the 120-byte message complete.

Given that the vulnerable version does not check whether the next packet can fit into the scratch buffer, data gets written past the end of the buffer and leads to a buffer overflow.

"For example, a 120-byte handshake message can arrive as 120 fragments.

Every fragment has length=120, but each one can have fragment_length=1," security researcher Sina Kheirkhah explained.

The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated.

What started as stealthy targeting via zero-day exploits has now become widespread exploitation, fueled by the publication of a root-cause analysis and a proof-of-concept exploit for CVE-2026-88771, which is remotely exploitable on unpatched devices with the default configuration.

Rumors about a NetScaler zero-day being exploited in the wild started late last week, and were confirmed when Citrix published a security advisory after the release of patches for eight critical and high-risk vulnerabilities.

Citrix also provided a detection script customers could use to check for evidence of compromise, but acknowledged it since attackers often change tactics, techniques, and procedures (TTPs) and infrastructure.

What happened

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).

the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said .

What changed

This parsing inconsistency can be exploited by an attacker to craft a malicious record that makes the record look small, while the actual data being copied to the buffer is much larger in size, resulting in an overflow.

After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data." watchTowr's analysis further found that this overflow can be weaponized to divert control flow to arbitrary shellcode with root-level privileges by using the mprotect() system call to defeat NX (no-execute) protections.

The disclosure comes a day after the preemptive exposure management company released a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.

Who is affected

Once every position has arrived, the server considers the 120-byte message complete.

Given that the vulnerable version does not check whether the next packet can fit into the scratch buffer, data gets written past the end of the buffer and leads to a buffer overflow.

Why it matters

"For example, a 120-byte handshake message can arrive as 120 fragments.

Every fragment has length=120, but each one can have fragment_length=1," security researcher Sina Kheirkhah explained.

Technical details

The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated.

What started as stealthy targeting via zero-day exploits has now become widespread exploitation, fueled by the publication of a root-cause analysis and a proof-of-concept exploit for CVE-2026-88771, which is remotely exploitable on unpatched devices with the default configuration.

Rumors about a NetScaler zero-day being exploited in the wild started late last week, and were confirmed when Citrix published a security advisory after the release of patches for eight critical and high-risk vulnerabilities.

Response

Citrix also provided a detection script customers could use to check for evidence of compromise, but acknowledged it since attackers often change tactics, techniques, and procedures (TTPs) and infrastructure.

Xavier Bellekens, CEO of cyber deception and threat intelligence firm Lupovis, told Help Net Security that their sensor network started recording live exploitation attempts against Citrix NetScaler within minutes of a PoC exploit for CVE-2026-88771 being released by watchTowr Labs.

What security teams should do

The attempts they captured were opportunistic, aimed at scanning the whole internet for exposed, unpatched appliances.

CERT-EU also posted technical details and threat-hunting advice and pointers for organizations, informed by the investigation it started after hearing rumors of exploitation.

What remains unknown

It’s not clear who is behind the exploitation attempts but in 2025, a cyber intrusion linked to China-based group Salt Typhoon targeted a Citrix zero day.

Attribution

The Hacker News: Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

Help Net Security: The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated.

The Hacker News: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

NCSC-UK: The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmFortinet warns of critical FortiMail flaw exploited in zero-day attacksBleepingComputer · 2 Oct 2026, 4:12 amKiteworks patches max severity code injection vulnerabilityBleepingComputer · 1 Oct 2026, 7:21 pm