
Actively Exploited Citrix NetScaler Flaw Gives Attackers Full Con
A critical memory overflow bug in Citrix NetScaler ADC and Gateway has been patched after active exploitation was observed. Patch immediately to stop unauthenti…
A severe vulnerability in Citrix NetScaler ADC and Gateway appliances is being actively exploited in the wild, enabling attackers to run arbitrary commands with the highest system privileges without needing any login credentials. Security researchers at watchTowr have published detailed technical analysis showing how the flaw, tracked as CVE-2026-88772, allows a remote attacker to send specially crafted network packets that overwrite the device’s memory and hijack its operation.
The bug resides in how NetScaler’s Packet Processing Engine (NSPPE, the internal software component that handles network traffic) processes the Datagram Transport Layer Security (DTLS) handshake. DTLS is a protocol used to secure data sent over UDP, for example in real-time communication. During the initial handshake, a message can be split into many fragments. The problem is that NSPPE trusts the small fragment size declared by the sender without checking the total data being reassembled. A single handshake message can arrive as 120 fragments, each claiming to be only one byte long while in reality carrying a much larger payload. As the appliance joins these pieces, it copies far more data than the receiving buffer can hold, causing a buffer overflow that corrupts adjacent memory.
watchTowr researcher Sina Kheirkhah explained that the overflow is possible because NSPPE stores incoming packets in NetScaler Buffers (NSBs) and then stitches them into a fixed-size scratch buffer of only 35,840 bytes. Since the vulnerable version does not verify that each incoming packet fits, data spills past the buffer’s end. "The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message," Kheirkhah said. "However, NSPPE keeps almost the whole record in an NSB. After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data." That is more than four times the buffer’s capacity.
The analysis further shows that an attacker can weaponize this memory corruption to redirect the program’s execution flow to attacker-supplied shellcode, a small piece of malicious code delivered through the network. By calling the mprotect() system function, the attacker can mark a region of memory as executable, bypassing the No-eXecute (NX) protection that modern processors use to prevent code from running in data areas. This technique yields full remote code execution with root-level privileges, meaning the attacker gains control of the appliance at the deepest operating system level.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has described the flaw as an improper restriction of operations within the bounds of a memory buffer, with a CVSS score of 9.5 out of 10, reflecting its critical severity. The advisory confirms that successful exploitation could allow remote code execution or denial-of-service. Citrix has released patches to fix the vulnerability, and all organizations using NetScaler ADC or Gateway should update immediately. The disclosure comes one day after watchTowr released a proof-of-concept for CVE-2026-88771, another vulnerability that has been abused alongside CVE-2026-88772 in ongoing attacks, suggesting a coordinated exploitation campaign.
For website owners and businesses that rely on NetScaler appliances to protect their applications, the implications are direct: an unauthenticated attacker on the network can seize the device that guards web resources, intercept traffic, modify content, or move laterally into the internal network. For organizations running such critical network appliances, AEU-I provides security-first IT infrastructure and consulting to help maintain hardened configurations and apply patches promptly.
Si të Mbroheni
- If your company uses a Citrix NetScaler ADC or Gateway appliance, ask your IT team to download and install the latest security updates from Citrix right away.
- Make sure the NetScaler management interface is not accessible directly from the internet to reduce the risk of remote attacks.
- Restrict which IP addresses can send DTLS traffic to your NetScaler to only trusted sources, if possible.
- Review your appliance’s access and error logs for signs of unusual handshake activity or crashes that could indicate an exploitation attempt.
- If you outsource network management, contact your provider immediately to confirm they have patched all affected devices.
Dobësitë & Zgjidhjet
- CVE-2026-88771 A related vulnerability also actively exploited in the wild alongside CVE-2026-88772; a proof-of-concept has been released. Shiko zgjidhjen & detajet →
- CVE-2026-88772 A critical memory overflow in Citrix NetScaler ADC and Gateway DTLS handling that enables remote code execution or denial-of-service; fixed via vendor security updates. Shiko zgjidhjen & detajet →
Termat e Shpjeguar
- DTLS (Datagram Transport Layer Security) A security protocol that protects data sent over fast, connectionless networks (like video calls), similar to TLS but designed for UDP traffic.
- NSPPE (NetScaler Packet Processing Engine) The internal software inside a Citrix NetScaler appliance that handles and processes all network data packets.
- Buffer overflow A dangerous error where a program writes more data into a memory area than it can hold, often letting attackers overwrite critical parts of the system.
- Shellcode A small piece of attack code that an intruder injects into a running program to take control of it and execute arbitrary commands.
- mprotect() A system command that can change access permissions on memory pages; attackers abuse it to turn a non-executable region into one where code can run.
- NX (No-eXecute) A hardware protection that marks certain memory areas as non-executable, preventing injected attack code from running, unless the attacker finds a way to disable it.
- CVSS (Common Vulnerability Scoring System) A standard way to rate the severity of a security flaw on a scale from 0 to 10, where higher numbers mean greater risk.