Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution


Ravie LakshmananSep 30, 2026Vulnerability / Network Security

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that’s rooted in the NetScaler Packet Processing Engine (NSPPE).

“Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.

The issue, per watchTowr, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header’s fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.

This parsing inconsistency can be exploited by an attacker to craft a malicious record that makes the record look small, while the actual data being copied to the buffer is much larger in size, resulting in an overflow.

Cybersecurity

“For example, a 120-byte handshake message can arrive as 120 fragments. Every fragment has length=120, but each one can have fragment_length=1,” security researcher Sina Kheirkhah explained. “Their offsets would be 0, 1, 2, and so on up to 119. Once every position has arrived, the server considers the 120-byte message complete. Joining those pieces is called reassembly.”

Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes. Given that the vulnerable version does not check whether the next packet can fit into the scratch buffer, data gets written past the end of the buffer and leads to a buffer overflow.

“The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message,” Kheirkhah said. “However, NSPPE keeps almost the whole record in an NSB. After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data.”

watchTowr’s analysis further found that this overflow can be weaponized to divert control flow to arbitrary shellcode with root-level privileges by using the mprotect() system call to defeat NX (no-execute) protections.

The disclosure comes a day after the preemptive exposure management company released a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.



Source link

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *