CVE -2026-88772 is one of the most dangerous vulnerabilities disclosed this year in Citrix NetScaler ADC and NetScaler Gateway, with a CVSS score of 9.5 and active exploitation. Cybersecurity researchers have published full technical details of the flaw, revealing a pre-auth path that leads to the execution of arbitrary shellcode with root. The disclosure comes at a critical time, as the vulnerability is already being used in real-world attacks alongside a second serious vulnerability, CVE-2026-88771.

The issue is in the way the NetScaler Packet Processing Engine (NSPPE) handles the Datagram Transport Layer Security (DTLS). Specifically, it is a memory overflow bug — memory overflow error — that allows an unauthenticated attacker to execute code remotely or cause a denial-of-service (DoS) on the system. The US Cybersecurity and Infrastructure Security Agency (CISA) has already included the vulnerability in its list of known exploitable vulnerabilities, urging organizations to immediately apply the available security updates.
Citrix NetScaler is widely used by enterprises and government organizations worldwide as an Application Delivery Controller (ADC) and VPN Gateway. This means that the attack surface is huge: thousands of systems exposed to the internet may be vulnerable, especially those that have not yet applied the necessary updates. In Europe and Greece, many companies use NetScaler for remote employee access, making immediate action imperative.
See also: CVE-2026-19490: The critical vulnerability in Citrix NetScaler
CVE-2026-88772: How the vulnerability works in Citrix NetScaler
To understand the severity of CVE-2026-88772, we need to consider how DTLS handles fragmented messages during the handshake. DTLS is a variant of TLS designed for UDP-based protocols, and is often used in VPN and communications. The issue was discovered by researchers at watchTowr, who discovered that NetScaler blindly trusts the declared fragment size in the fragment_length of the handshake header.
Security researcher Sina Kheirkhah clearly explained the exploit mechanism: a 120-byte handshake message can reach up to 120 fragments . Each fragment has length=120 , but fragment_length=1 . Their offsets are 0, 1, 2 , and so on up to 119. Once all the positions are reached, the server considers the 120-byte message complete and begins the reassembly process — assembling the fragments into a single message. This inconsistency in data parsing is the root of the problem.

Each incoming packet of 1,459 bytes is stored in NetScaler Buffers (NSBs) , which are then concatenated into a single scratch buffer of just 35,840 bytes . The critical flaw is that the vulnerable version does not check whether the next packet fits in the scratch buffer, resulting in data being written beyond the buffer's boundaries — a classic buffer overflow scenario . After 120 writes , the handshake message is considered complete, but the NSB chain contains approximately 174 KB of data instead of the expected 120 bytes .
CVE-2026-88772: From Buffer Overflow to Shellcode Execution
watchTowr's analysis revealed that this overflow can be used to redirect program execution to arbitrary shellcode. Attackers use the mprotect() to bypass the NX (No-Execute), which normally prevent code from executing in memory areas intended only for data. The result is code execution with root, giving the attacker full control of the system.
See also: Citrix NetScaler: Critical Authentication Bypass Vulnerability
What makes CVE-2026-88772 particularly dangerous is that it requires no authentication — an attacker doesn’t need to have an account or credentials to exploit the vulnerability. All that’s needed is access to the NetScaler DTLS network service , which in many cases is exposed directly to the internet. This feature — known as a pre -authentication exploit — dramatically increases the risk, as there’s no additional hurdle for an attacker to overcome.
The disclosure of the technical details came a day after the release of a proof-of-concept (PoC) exploit for CVE-2026-88771, a secondcritical vulnerability that is being used alongside CVE-2026-88772 in real-world attacks. The combined use of the two vulnerabilities significantly increases the capabilities of attackers, allowing for more complex and effective attacks against infrastructures based on Citrix NetScaler. According to The Hacker News, watchTowr is the company that claimed responsibility for disclosing both vulnerabilities.

Addressing CVE-2026-88772: Protection Steps for Administrators
Citrix has already released security updates to address CVE-2026-88772 , and system administrators are urged to apply them immediately. CISA has issued a related warning, emphasizing that the vulnerability is being actively exploited and there is no time for delay. Organizations using NetScaler ADC or NetScaler Gateway should immediately check their software version and apply the available updates.
See also: Citrix NetScaler – CISA: Vulnerability patching by September 30
In addition to immediately applying patches, experts recommend a number of additional protection measures. First, administrators should limit the exposure of DTLS to the Internet, allowing access only from trusted IP addresses. Second, monitoring logs for suspicious activity in DTLS handshake services can help detect exploit attempts early. Third, using a Web Application Firewall (WAF) with updated rules can provide an additional layer of defense against known exploits.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
For organizations that cannot immediately apply the updates, Citrix and CISA recommend disabling the DTLS service as a temporary measure unless it is absolutely necessary for the organization to function.
