CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8944

As cited

Copy frozen at (site build).

vulnerabilities

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Researchers have disclosed technical details of CVE-2026-88772, a critical memory overflow vulnerability in Citrix NetScaler ADC and Gateway's Datagram Transport Layer Security (DTLS) protocol handling. The flaw, with a CVSS score of 9.5, is under active exploitation and affects pre-authentication code paths that can lead to remote code execution (RCE).

Why it matters: Organizations running Citrix NetScaler ADC or Gateway are at immediate risk of pre-authentication RCE exploitation; prioritize patching as the vulnerability is actively exploited in the wild.

VendorsCitrix
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary