CVE-2026-88772 — Citrix NetScaler ADC/Gateway DTLS Memory Overflow (RCE/DoS)
September 27, 2026 · 505 views
Memory overflow in Citrix NetScaler ADC and NetScaler Gateway DTLS handling (UDP, typically 443) can lead to remote code execution or denial of service. DTLS is on by default for Gateway VPN virtual servers unless -dtls OFF. Fixed at 14.1-73.37+ and 13.1-64.23+; CTX697096 reports active exploitation of CVE-2026-88772 with sibling CVEs. CVSS 4.0 9.5 Critical. PoC fingerprints Gateway, compares build strings, optional benign DTLS probe — no overflow trigger.
Description
Overview
CVE-2026-88772 affects Citrix NetScaler ADC and NetScaler Gateway (Cloud Software Group). A memory overflow in DTLS (datagram TLS over UDP, commonly 443) can result in remote code execution or denial of service. Exploitation requires DTLS to be enabled. On Gateway, DTLS is enabled by default for VPN virtual servers unless an administrator configured -dtls OFF. DTLS-type vServers are also in scope.
Citrix advisory CTX697096 (cluster CVE-2026-88771 through 88778) documents fixes and states active exploitation of 88771 and 88772 on unmitigated appliances. Builds such as 14.1-73.32 and 13.1-63.21 do not remediate this issue.
| Product | Fixed at | |---------|----------| | ADC / Gateway 14.1 | 14.1-73.37 and later | | ADC / Gateway 13.1 | 13.1-64.23 and later | | ADC 14.1 FIPS | 14.1-73.37 FIPS | | ADC 13.1 FIPS / NDcPP | 13.1.37.279 |
CVSS 4.0: 9.5 CRITICAL (AV:N/AC:H/PR:N/UI:N, high confidentiality, integrity, and availability impact).
Open source PoC: https://github.com/murrez/CVE-2026-88772
PoC page: https://pocbit.org/pocs/cve-2026-88772
This repository fingerprints Gateway/ADC login surfaces, parses build strings when exposed, checks UDP/443, and optionally sends a benign DTLS ClientHello probe. It does not ship the memory overflow trigger (weaponized exploitation has been reported in the wild).
Bundled tool (Python 3)
pip install -r requirements.txt
python poc.py -u https://vpn.example.com --mode check
python poc.py -u https://vpn.example.com --mode check --dtls-probe
python poc.py -u https://vpn.example.com --build 14.1-73.32 --mode check
python poc.py --list targets.example.txt --mode check -j 12
Impact
Internet-facing NetScaler Gateway VPN endpoints with default DTLS may be at critical risk while unpatched. Successful exploitation can compromise the appliance or disrupt VPN availability. Treat as incident-response priority if CTX697096 thresholds are not met.
Remediation
- Upgrade to 14.1-73.37+, 13.1-64.23+, or the applicable FIPS/NDcPP builds listed in CTX697096.
- If patching is delayed, consider disabling DTLS on affected VPN vServers per vendor guidance (understand client impact).
- Restrict management and VPN interfaces; monitor for anomalous UDP/443 activity.
- Hunt for indicators per Citrix and national CSIRT guidance after patching.
Legal and ethical use
Authorized testing and incident response only. Do not send crash-oriented payloads against production appliances you do not own.
References
- NVD — CVE-2026-88772
- GitHub PoC — murrez/CVE-2026-88772
- Citrix CTX697096 (NetScaler security bulletin for CVE-2026-88771–88778)
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- IoT / OTCVE-2026-100740high
CVE-2026-100740 — D-Link DIR-895L L2TP Host Name AVP Out-of-Bounds Write
Out-of-bounds write (CWE-787 / CWE-119) in D-Link DIR-895L firmware A1_102b07 L2TP tunnel_set_params() — Host Name AVP length clamped to 127 but NUL written at peer_hostname[len+1] on a 128-byte buffer. Remote attack over UDP 1701 when L2TP is active. PoC fingerprints the router, probes UDP 1701, optional lab-only --oob-send trigger. No vendor fix listed in NVD at publication.
- IoT / OTCVE-2026-13249critical
CVE-2026-13249 — Honeywell PD45 Unauthenticated File Upload (RCE)
Unauthenticated arbitrary file upload on Honeywell PD45 Industrial Printer HTTPS web admin (firmware F10.19.010040 through before F10.22.030745) — CWE-306/434/78, CVSS 9.8 Critical. Attacker-controlled files may execute on the device. Fixed in firmware F10.22.030745.
- JoomlaCVE-2026-97160critical
CVE-2026-97160 — Joomla UP Plugin PHP Code Injection ({up php=} eval)
PHP code injection (CWE-94, CVSS 4.0 9.4 Critical) in UP (Universal Plugin) for Joomla (plg_content_up, lomart.fr) 5.0.0–5.2.0 and 6.0.0–6.0.29 via {up php=...} shortcodes processed with eval(). Author save/render bypass on older builds can expose execution to all visitors. Fixed in 5.2.1 and 6.1.0.
- JoomlaCVE-2026-94132critical
CVE-2026-94132 — AcyMailing Enterprise Mailbox Attachment RCE (Joomla)
AcyMailing Enterprise for Joomla < 11.1.0 (through 11.0.5): POP3 mailbox actions save MIME attachments without extension checks to media/com_acym/upload/, enabling RCE when an attacker can email the monitored inbox. CWE-434, CVSS 4.0 9.5 Critical (AT:P). Fixed in 11.1.0.