Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Summary

Researchers have disclosed technical details for CVE-2026-88772, a critical vulnerability in Citrix NetScaler ADC and Gateway that is being actively exploited. The flaw is a memory overflow bug in the DTLS protocol handling.

IFF Assessment

FOE

This vulnerability allows for pre-authentication path to shellcode execution, posing a significant risk to systems and defenders.

Severity

8.1 High

CISA KEV: Listed as actively exploited. Federal patch due: September 30, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability allows attackers to gain unauthorized shell access to affected Citrix NetScaler devices without authentication. Defenders must prioritize patching affected systems immediately and monitor for signs of exploitation, as this critical flaw is already being actively exploited in the wild.

Read Full Story →