VMTech
Discuss a project →

Citrix NetScaler DTLS flaw exposes pre-auth code execution path

Citrix NetScaler DTLS flaw exposes pre-auth code execution path

Critical NetScaler flaw is under active exploitation

Technical analysis has revealed how CVE-2026-88772, a critical vulnerability in Citrix NetScaler ADC and NetScaler Gateway, can provide a pre-authentication path to shellcode execution. The flaw has a CVSS score of 9.5 and is being actively exploited in the wild.

The issue is a memory overflow in Datagram Transport Layer Security (DTLS) protocol handling within the NetScaler Packet Processing Engine (NSPPE). CISA said the improper restriction of operations within a memory buffer could allow remote code execution or denial of service.

Security firm watchTowr traced the condition to inconsistent processing of fields in a DTLS handshake header. NetScaler trusts the declared size in the one-byte fragment_length field even where the header's length field indicates that the full message is 120 bytes long.

How crafted DTLS fragments trigger the overflow

An attacker can send a 120-byte handshake message as 120 fragments. Each fragment declares a length of 120 bytes but a fragment length of one byte, with offsets progressing from 0 through 119. Once each position is received, the target regards the 120-byte message as complete and begins reassembly.

Each received packet can be 1,459 bytes and is retained in NetScaler Buffers, or NSBs. NSPPE then stitches the data into a scratch buffer limited to 35,840 bytes. The vulnerable implementation does not verify that the next packet fits before copying it into that buffer.

The crafted records cause the reassembly code to believe that every record contributes a single byte, while NSPPE keeps almost the entire record in its NSB. After 120 records, the message is considered complete but its NSB chain can contain about 174 KB of data, causing writes beyond the scratch buffer.

Potential impact for NetScaler deployments

watchTowr found that the overflow can be weaponised to redirect control flow to arbitrary shellcode with root-level privileges. Its analysis describes use of the mprotect() system call to defeat NX, or no-execute, protections.

The disclosure followed watchTowr's proof-of-concept release for CVE-2026-88771, another NetScaler issue reported as having been abused with CVE-2026-88772 in real-world attacks. Organisations operating NetScaler ADC or Gateway should treat the active exploitation and pre-authentication nature of this flaw as a priority when applying Citrix's available fixes and reviewing exposed systems.

#cybersecurity#netscaler#vulnerability#remotecodeexecution
Open analytics
On the site 3 views
min read 3 30.09.2026
Instagram

Citrix NetScaler DTLS flaw exposes pre-auth code execution path

Open the post on Instagram ↗