Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US Senator Blumenthal Calls Tether’s USDT a ‘Superhighway’ for Iranian Sanctions Evasion

    September 30, 2026

    NSTGRO 2026

    September 30, 2026

    Pratap Singh Chundawat rescued a leopard from a well. He died in the line of duty, aged 40

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US Senator Blumenthal Calls Tether’s USDT a ‘Superhighway’ for Iranian Sanctions Evasion
    • NSTGRO 2026
    • Pratap Singh Chundawat rescued a leopard from a well. He died in the line of duty, aged 40
    • Aliko Dangote to launch Kenya oil refinery amid land protest in Lamu
    • Sixteen English councils spend more than 80% of core funding on social care | Social care
    • Andy Burnham: UK could ‘go all the way’ by rejoining EU | Andy Burnham
    • Trump orders US government to call AI ‘Super Intelligence’
    • Can we jail a superintelligence?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 30, 2026Vulnerability / Network Security

    Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that’s rooted in the NetScaler Packet Processing Engine (NSPPE).

    “Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial-of-service,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.

    The issue, per watchTowr, is that NetScaler implicitly trusts the declared fragment size in the DTLS handshake header’s fragment_length field (i.e., 1 byte), while the header simultaneously claims that the complete message, as denoted by the length field, is 120 bytes long.

    This parsing inconsistency can be exploited by an attacker to craft a malicious record that makes the record look small, while the actual data being copied to the buffer is much larger in size, resulting in an overflow.

    Cybersecurity

    “For example, a 120-byte handshake message can arrive as 120 fragments. Every fragment has length=120, but each one can have fragment_length=1,” security researcher Sina Kheirkhah explained. “Their offsets would be 0, 1, 2, and so on up to 119. Once every position has arrived, the server considers the 120-byte message complete. Joining those pieces is called reassembly.”

    Each received packet of 1,459 bytes is stored in NetScaler Buffers (NSBs), which is then stitched into a single scratch buffer of only 35,840 bytes. Given that the vulnerable version does not check whether the next packet can fit into the scratch buffer, data gets written past the end of the buffer and leads to a buffer overflow.

    “The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message,” Kheirkhah said. “However, NSPPE keeps almost the whole record in an NSB. After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data.”

    watchTowr’s analysis further found that this overflow can be weaponized to divert control flow to arbitrary shellcode with root-level privileges by using the mprotect() system call to defeat NX (no-execute) protections.

    The disclosure comes a day after the preemptive exposure management company released a proof-of-concept (PoC) for CVE-2026-88771, which has been abused alongside CVE-2026-88772 in real-world attacks.

    Citrix CVE202688772 details Execution exploit NetScaler path PreAuth Shellcode show
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Can we jail a superintelligence?

    Mass Heat Wave Deaths in Europe Show Climate Extremes Are Outpacing Adaptation Efforts

    High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    Pentagon Personnel Agency Data Breach Impacts 3 Million People

    RemoteThreat Launches With $7 Million for Offensive Operations Platform

    160-million-year-old proteins show surprising power against superbugs

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US Senator Blumenthal Calls Tether’s USDT a ‘Superhighway’ for Iranian Sanctions Evasion

    September 30, 2026

    NSTGRO 2026

    September 30, 2026

    Pratap Singh Chundawat rescued a leopard from a well. He died in the line of duty, aged 40

    September 30, 2026

    Aliko Dangote to launch Kenya oil refinery amid land protest in Lamu

    September 30, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US Senator Blumenthal Calls Tether’s USDT a ‘Superhighway’ for Iranian Sanctions Evasion

    September 30, 2026

    NSTGRO 2026

    September 30, 2026

    Pratap Singh Chundawat rescued a leopard from a well. He died in the line of duty, aged 40

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.