POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
IoT / OTcritical

CVE-2026-88772 — Citrix NetScaler ADC/Gateway DTLS Memory Overflow (RCE/DoS)

September 27, 2026 · 505 views

Memory overflow in Citrix NetScaler ADC and NetScaler Gateway DTLS handling (UDP, typically 443) can lead to remote code execution or denial of service. DTLS is on by default for Gateway VPN virtual servers unless -dtls OFF. Fixed at 14.1-73.37+ and 13.1-64.23+; CTX697096 reports active exploitation of CVE-2026-88772 with sibling CVEs. CVSS 4.0 9.5 Critical. PoC fingerprints Gateway, compares build strings, optional benign DTLS probe — no overflow trigger.

#citrix#netscaler#vpn#dtls#adc#gateway#network#rce

CVE:

CVE-2026-88772

Date:

2026-09-27

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-88772 affects Citrix NetScaler ADC and NetScaler Gateway (Cloud Software Group). A memory overflow in DTLS (datagram TLS over UDP, commonly 443) can result in remote code execution or denial of service. Exploitation requires DTLS to be enabled. On Gateway, DTLS is enabled by default for VPN virtual servers unless an administrator configured -dtls OFF. DTLS-type vServers are also in scope.

Citrix advisory CTX697096 (cluster CVE-2026-88771 through 88778) documents fixes and states active exploitation of 88771 and 88772 on unmitigated appliances. Builds such as 14.1-73.32 and 13.1-63.21 do not remediate this issue.

| Product | Fixed at | |---------|----------| | ADC / Gateway 14.1 | 14.1-73.37 and later | | ADC / Gateway 13.1 | 13.1-64.23 and later | | ADC 14.1 FIPS | 14.1-73.37 FIPS | | ADC 13.1 FIPS / NDcPP | 13.1.37.279 |

CVSS 4.0: 9.5 CRITICAL (AV:N/AC:H/PR:N/UI:N, high confidentiality, integrity, and availability impact).

Open source PoC: https://github.com/murrez/CVE-2026-88772

PoC page: https://pocbit.org/pocs/cve-2026-88772

This repository fingerprints Gateway/ADC login surfaces, parses build strings when exposed, checks UDP/443, and optionally sends a benign DTLS ClientHello probe. It does not ship the memory overflow trigger (weaponized exploitation has been reported in the wild).

Bundled tool (Python 3)

pip install -r requirements.txt

python poc.py -u https://vpn.example.com --mode check
python poc.py -u https://vpn.example.com --mode check --dtls-probe
python poc.py -u https://vpn.example.com --build 14.1-73.32 --mode check
python poc.py --list targets.example.txt --mode check -j 12

Impact

Internet-facing NetScaler Gateway VPN endpoints with default DTLS may be at critical risk while unpatched. Successful exploitation can compromise the appliance or disrupt VPN availability. Treat as incident-response priority if CTX697096 thresholds are not met.

Remediation

  1. Upgrade to 14.1-73.37+, 13.1-64.23+, or the applicable FIPS/NDcPP builds listed in CTX697096.
  2. If patching is delayed, consider disabling DTLS on affected VPN vServers per vendor guidance (understand client impact).
  3. Restrict management and VPN interfaces; monitor for anomalous UDP/443 activity.
  4. Hunt for indicators per Citrix and national CSIRT guidance after patching.

Legal and ethical use

Authorized testing and incident response only. Do not send crash-oriented payloads against production appliances you do not own.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →