Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Дата публикации: 30-09-2026 05:30:30

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Основное содержимое страницы с новостью.

Ravie LakshmananSep 30, 2026Vulnerability / Network Security

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).

"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.

The issue, per watchTowr, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.

This parsing inconsistency can be exploited by an attacker to craft a malicious record that makes the record look small, while the actual data being copied to the buffer is much larger in size, resulting in an overflow.

"For example, a 120-byte handshake message can arrive as 120 fragments. Every fragment has length=120, but each one can have fragment_length=1," security researcher Sina Kheirkhah explained. "Their offsets would be 0, 1, 2, and so on up to 119. Once every position has arrived, the server considers the 120-byte message complete. Joining those pieces is called reassembly."

Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes. Given that the vulnerable version does not check whether the next packet can fit into the scratch buffer, data gets written past the end of the buffer and leads to a buffer overflow.

"The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message," Kheirkhah said. "However, NSPPE keeps almost the whole record in an NSB. After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data."

watchTowr's analysis further found that this overflow can be weaponized to divert control flow to arbitrary shellcode with root-level privileges by using the mprotect() system call to defeat NX (no-execute) protections.

The disclosure comes a day after the preemptive exposure management company released a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
2Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT07.930-09-2026
3Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation09.2627-09-2026
4Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung09.0327-09-2026
5Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager09.9530-09-2026
6Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets09.230-09-2026
7OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted08.3130-09-2026
8WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV09.7125-09-2026
9Два нулевых дня в Citrix NetScaler эксплуатируют неделями, администраторы отключают шлюзы09.1129-09-2026
10WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours013.5924-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.39. Источник: thehackernews.com.