Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Summary
Researchers have disclosed technical details for CVE-2026-88772, a critical vulnerability in Citrix NetScaler ADC and Gateway that is being actively exploited. The flaw is a memory overflow bug in the DTLS protocol handling.
IFF Assessment
This vulnerability allows for pre-authentication path to shellcode execution, posing a significant risk to systems and defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability allows attackers to gain unauthorized shell access to affected Citrix NetScaler devices without authentication. Defenders must prioritize patching affected systems immediately and monitor for signs of exploitation, as this critical flaw is already being actively exploited in the wild.