Skip to finding
§
High
Edge
Confirmed
CVE-2026-88772

Public exploit code turns NetScaler’s pre-authentication DTLS overflow into root-level execution.

A network caller needs only reachability to a DTLS-enabled Gateway VIP.

Affects

Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.

What it enables

Unauthenticated root-level code execution on a VPN gateway

Unauthenticated caller completes the DTLS cookie exchange→↓Attacker sends 120 crafted DTLS records whose fragment lengths understate retained data→↓NSPPE reassembles roughly 174 KB into a smaller scratch buffer→↓Forged objects redirect control flow through a ROP chain→↓Shellcode executes with root-level appliance privileges
Why this matters

Version-specific public code converts a reported memory-corruption condition into a reusable unauthenticated root-execution path.

Detail, proof-of-concept code and 5 sources
Required access

Network reachability to a DTLS-enabled NetScaler virtual server, normally UDP on the Gateway VIP

Affected versions

NetScaler ADC and Gateway 14.1 before 14.1-73.37, NetScaler ADC and Gateway 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279

Proof of concept

Public exploit code →

An unauthenticated caller can complete the DTLS cookie exchange before sending the malicious fragments.

The exploit sends 120 records whose understated fragment lengths make reassembly overflow a smaller scratch buffer with roughly 174 KB of retained data.

Forged objects redirect control flow through a ROP chain and execute shellcode as root; crafted DTLS traffic was also tied to pre-disclosure web-shell activity.

Citrix has shipped a patch, but pre-fix appliance images remain accepted.

Evidence
Citrix confirms exploitation and the DTLS memory-overflow-to-RCE primitiveUnit 42 ties crafted DTLS traffic to pre-disclosure web-shell activitywatchTowr published version-specific code that builds a control-flow hijack and shellcode payload
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026