
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-88772 is a memory buffer overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that enables unauthenticated remote code execution (RCE) or denial of service (DoS). It was published on September 27, 2026, and immediately added to CISA's Known Exploited Vulnerabilities (KEV) catalog the same day with a patch deadline of September 30, 2026. Affected versions include NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS/NDcPP; and NetScaler Gateway before 14.1-73.37 and before 13.1-64.23. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.5 (Critical) (GitHub Advisory, CISA KEV, Citrix Advisory).
The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a DTLS (Datagram Transport Layer Security) pre-authentication memory overflow in the NetScaler ADC and Gateway stack. According to watchTowr Labs' technical write-up, the flaw resides in the DTLS handling code and can be triggered over UDP/443 without any authentication, allowing an attacker to corrupt memory and achieve shellcode execution (watchTowr Labs). The attack vector is network-based with high attack complexity (AC:H), no privileges required, and no user interaction needed. A public PoC script (Python) was released by researcher 'murrez' on GitHub that fingerprints vulnerable systems by parsing build strings and sending benign DTLS probes, but does not include the weaponized memory overflow trigger (GitHub PoC). The weaponized exploit was observed in the wild prior to patch availability, with exploitation traced back to at least early September 2026 (Help Net Security).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code at root level on affected NetScaler ADC and Gateway appliances, or crash the service causing denial of service. In observed attacks, threat actors leveraged this vulnerability to deploy web shells (dubbed 'Whipshot'), establish persistent root-level backdoors, and deploy tunneling malware ('Slapshot') to pivot into internal networks — targeting government agencies, financial institutions, banks, telcos, and professional services organizations across Europe and North America (BleepingComputer, The Register, Mandiant/Google). Critically, patching alone does not evict attackers who have already established persistence via web shells or backdoors, requiring forensic triage post-patching (CISA KEV).
CVE-2026-88772 was exploited as a zero-day for at least three weeks before patches were released, with exploitation beginning in early September 2026 (CyberScoop). It was added to CISA's KEV catalog on September 27, 2026, with a mandatory federal agency patch deadline of September 30, 2026 (CISA KEV). A detection-only PoC (not weaponized) is publicly available on GitHub (GitHub PoC), and watchTowr Labs published a detailed technical analysis of the DTLS memory overflow mechanism (watchTowr Labs). Exploitation has been attributed to suspected state-sponsored threat actors, with Mandiant/Google reporting custom malware (Whipshot web shells and Slapshot tunneling tools) deployed against dozens of organizations (Mandiant/Google, SC World). The EPSS score is approximately 1.3% (69th percentile), and approximately 50,000+ internet-facing NetScaler instances were estimated to remain exposed at time of disclosure (Help Net Security).
/var/netscaler/logon/, /netscaler/ns_gui/); unexpected binary files or scripts in system directories; new or modified files with recent timestamps inconsistent with patch activity.Citrix released patched versions on September 27–28, 2026. Organizations should upgrade immediately to: NetScaler ADC 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1.37.279 FIPS/NDcPP; NetScaler Gateway 14.1-73.37 or 13.1-64.23 (Citrix Advisory). CISA mandated federal agencies patch by September 30, 2026, and requires forensic triage per BOD 26-04 because patching does not remove backdoors already installed by attackers — organizations should follow Citrix's CTX694799 guidance to check for signs of compromise before and after patching (CISA KEV). As interim mitigations, restrict network access to management interfaces, implement network segmentation to limit exposure of NetScaler appliances to the internet, and monitor for anomalous DTLS traffic on UDP/443. If patching is not immediately possible, consider taking internet-facing NetScaler appliances offline until patched.
Citrix confirmed active exploitation in a security bulletin (CTX697096) published September 27–28, 2026, after security researchers (including watchTowr) had already publicly warned of unpatched zero-day exploitation over the preceding weekend — drawing criticism for delayed official disclosure (CyberScoop). CISA, NCSC (UK), ACSC (Australia), and multiple national CERTs issued urgent advisories urging immediate patching (NCSC UK, ACSC). Researcher Kevin Beaumont (@GossiTheDog) and others on social media highlighted the severity and the disclosure delay, with some administrators reportedly shutting down NetScaler appliances preemptively before official patches were available (BleepingComputer). Mandiant/Google, Rapid7, Sophos, Palo Alto Unit 42, and Sygnia all published threat intelligence reports confirming mass exploitation and custom malware deployment (Rapid7, Sophos, Unit 42).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."