CVE-2026-88772
Overview
This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.
Vulnerability Description
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Impact
An attacker can exploit this vulnerability remotely without any authentication or user interaction to execute arbitrary code on the affected system or cause a denial of service by crashing the service. This enables full system compromise, including potential unauthorized access to sensitive data and lateral movement within the network. The ability to execute code at the system level can lead to persistent control over the appliance, severely impacting business continuity and security posture.
Solution
Citrix has released security updates addressing this vulnerability in NetScaler ADC and Gateway versions 14.1-73.37 and 13.1-64.23, including patches for FIPS and NDcPP builds. Administrators should apply these specific version upgrades as detailed in Citrix Security Bulletin CTX697096. The advisory provides comprehensive patch installation instructions and recommended mitigation steps. Refer to the official Citrix support article for exact patch versions and deployment guidance.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
murrez/CVE-2026-88772
CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build v...
|
murrez | 2 | 0 | 2026-09-27 | View |
Threat Feed
6 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Active exploitation confirmed — vendor: Citrix, product: NetScaler ADC and NetScaler Gateway
Proof-of-concept code is publicly available for this vulnerability
Active exploitation confirmed with 3364 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns ML
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.