CITRIX NetScaler ADC and NetScaler Gateway have been widely exploited in the wild after a critical flaw, CVE-2026-88772, was patched. The memory overflow flaw lies in how the Datagram Transport Layer Security (DTLS) handling works inside the NetScaler Packet Processing Engine (NSPPE).
The vulnerability arises because NetScaler trusts the fragment length in the DTLS handshake header (1 byte) while the overall message length can be much larger, enabling an attacker to craft a malicious DTLS record that appears small but actually carries a much larger payload. Security researchers explain that a 120‑byte handshake message could arrive as 120 fragments, with each fragment indicating a length of only one byte, allowing the attacker to trigger a reassembly process that overflows the NSPPE buffers.
If successfully exploited, the overflow can be weaponised to divert control flow to arbitrary shellcode with root‑level privileges by calling mprotect() to bypass NX protections.
The description in the report notes that multiple small fragments are stored in NetScaler Buffers (NSBs) and then stitched into a scratch buffer of 35,840 bytes; the vulnerable version does not ensure the next fragment will fit, so data is written past the buffer end, producing a large internal data stash (reported as around 174 KB in some analyses).
The article states that this constitutes pre‑auth remote code execution and highlights that CVE-2026-88771 and CVE-2026-88772 have been used in real‑world attacks, with CVE-2026-88772 being the more critical of the two. Responders are advised to apply the patch and monitor for evidence of exploitation.