Citrix NetScaler CVE202688772 Exploit Details Show PreAuth Path to Shellcode Execution

Image for article Citrix NetScaler CVE202688772 Exploit Details Show PreAuth Path to Shellcode Execution
News Source : Internet

News Summary

  • Vulnerability tracked as CVE-2026-88772 (CVSS score: 9.5) It has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling.
  • The issue, per watchTowr, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte) This parsing inconsistency can be exploited by an attacker to craft a malicious record that makes the record look small.
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

Must read Articles