Cybersecurity researchers disclosed technical details of CVE-2026-88772, a critical Citrix NetScaler ADC and Gateway flaw that is being actively exploited in the wild. The bug is a DTLS-related memory overflow in the NetScaler Packet Processing Engine and can lead to remote code execution or denial-of-service. #CVE-2026-88772 #CitrixNetScaler #NetScalerADC #NetScalerGateway #NSPPE
Keypoints
- CVE-2026-88772 is a critical flaw in Citrix NetScaler ADC and Gateway.
- The vulnerability is a DTLS memory overflow in the NetScaler Packet Processing Engine.
- Attackers can exploit a fragment length parsing inconsistency to trigger buffer overflow.
- The flaw may enable remote code execution or denial-of-service.
- watchTowr found the overflow can be turned into root-level shellcode execution.
Read More: https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html