Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Read original article ↗AI Summary
A critical buffer overflow vulnerability, CVE-2026-88772, in Citrix NetScaler ADC and Gateway has been actively exploited in the wild. The flaw exists in the Datagram Transport Layer Security (DTLS) protocol handling within the NetScaler Packet Processing Engine (NSPPE), where an inconsistency in fragment size validation leads to a heap-based buffer overflow. This allows unauthenticated remote attackers to execute arbitrary shellcode with root privileges by triggering memory corruption during packet reassembly. The vulnerability enables remote code execution due to improper bounds checking, and exploitation techniques have been demonstrated using mprotect() to bypass NX protections.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.