CVE-2026-88772: 
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-88772 is a memory buffer overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that enables unauthenticated remote code execution (RCE) or denial of service (DoS). It was published on September 27, 2026, and immediately added to CISA's Known Exploited Vulnerabilities (KEV) catalog the same day with a patch deadline of September 30, 2026. Affected versions include NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS/NDcPP; and NetScaler Gateway before 14.1-73.37 and before 13.1-64.23. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.5 (Critical) (GitHub Advisory, CISA KEV, Citrix Advisory).

Technical details

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a DTLS (Datagram Transport Layer Security) pre-authentication memory overflow in the NetScaler ADC and Gateway stack. According to watchTowr Labs' technical write-up, the flaw resides in the DTLS handling code and can be triggered over UDP/443 without any authentication, allowing an attacker to corrupt memory and achieve shellcode execution (watchTowr Labs). The attack vector is network-based with high attack complexity (AC:H), no privileges required, and no user interaction needed. A public PoC script (Python) was released by researcher 'murrez' on GitHub that fingerprints vulnerable systems by parsing build strings and sending benign DTLS probes, but does not include the weaponized memory overflow trigger (GitHub PoC). The weaponized exploit was observed in the wild prior to patch availability, with exploitation traced back to at least early September 2026 (Help Net Security).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code at root level on affected NetScaler ADC and Gateway appliances, or crash the service causing denial of service. In observed attacks, threat actors leveraged this vulnerability to deploy web shells (dubbed 'Whipshot'), establish persistent root-level backdoors, and deploy tunneling malware ('Slapshot') to pivot into internal networks — targeting government agencies, financial institutions, banks, telcos, and professional services organizations across Europe and North America (BleepingComputer, The Register, Mandiant/Google). Critically, patching alone does not evict attackers who have already established persistence via web shells or backdoors, requiring forensic triage post-patching (CISA KEV).

Exploitability

CVE-2026-88772 was exploited as a zero-day for at least three weeks before patches were released, with exploitation beginning in early September 2026 (CyberScoop). It was added to CISA's KEV catalog on September 27, 2026, with a mandatory federal agency patch deadline of September 30, 2026 (CISA KEV). A detection-only PoC (not weaponized) is publicly available on GitHub (GitHub PoC), and watchTowr Labs published a detailed technical analysis of the DTLS memory overflow mechanism (watchTowr Labs). Exploitation has been attributed to suspected state-sponsored threat actors, with Mandiant/Google reporting custom malware (Whipshot web shells and Slapshot tunneling tools) deployed against dozens of organizations (Mandiant/Google, SC World). The EPSS score is approximately 1.3% (69th percentile), and approximately 50,000+ internet-facing NetScaler instances were estimated to remain exposed at time of disclosure (Help Net Security).

Exploitation steps

  1. Reconnaissance: Use Shodan, Censys, or similar tools to identify internet-facing Citrix NetScaler ADC and Gateway appliances. Parse build strings or version banners to confirm vulnerable versions (before 14.1-73.37 or 13.1-64.23). Check UDP/443 reachability for DTLS service availability.
  2. DTLS probe: Send crafted DTLS (Datagram TLS) packets over UDP/443 to the target NetScaler appliance. The vulnerability exists in the pre-authentication DTLS handling code, requiring no credentials.
  3. Memory overflow trigger: Send a specially crafted DTLS message that triggers an improper memory buffer operation (CWE-119), overflowing a buffer in the DTLS processing stack. This corrupts adjacent memory structures to gain control of execution flow.
  4. Shellcode execution: Inject shellcode into the overflowed buffer region. Upon triggering the overflow, the shellcode executes with root-level privileges on the NetScaler appliance.
  5. Web shell deployment (Whipshot): Drop a web shell (e.g., Whipshot) into the NetScaler web root or accessible directory to establish persistent, authenticated command execution over HTTP/HTTPS.
  6. Persistence and lateral movement: Deploy tunneling malware (Slapshot) to create covert C2 channels into the internal network. Create superuser accounts, exfiltrate NetScaler configuration (including credentials and certificates), and pivot to internal systems (watchTowr Labs, BleepingComputer, Mandiant/Google).

Indicators of compromise

  • Network: Unusual or malformed DTLS traffic over UDP/443 to NetScaler appliances from external IPs; unexpected outbound connections from the NetScaler to unknown external IPs; internal tunneling traffic consistent with Slapshot C2 activity.
  • File System: Presence of web shells (Whipshot) in NetScaler web directories (e.g., /var/netscaler/logon/, /netscaler/ns_gui/); unexpected binary files or scripts in system directories; new or modified files with recent timestamps inconsistent with patch activity.
  • Process: Unexpected child processes spawned by NetScaler daemons (e.g., shell interpreters, curl, wget); processes running as root that are not part of normal NetScaler operations.
  • Logs: NetScaler system logs showing DTLS handshake anomalies or crashes; HTTP access logs with unusual POST requests to web shell paths; authentication logs showing new superuser account creation or privilege escalation.
  • Configuration: Unauthorized new local user accounts with elevated privileges; modified NetScaler configuration files; unexpected changes to AAA or VPN policies.
  • CISA-recommended: Run the IOC-checking commands provided in Citrix's guidance (CTX694799) directly in the NetScaler console to identify indicators of exploitation (CISA KEV, Citrix Advisory).

Mitigation and workarounds

Citrix released patched versions on September 27–28, 2026. Organizations should upgrade immediately to: NetScaler ADC 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1.37.279 FIPS/NDcPP; NetScaler Gateway 14.1-73.37 or 13.1-64.23 (Citrix Advisory). CISA mandated federal agencies patch by September 30, 2026, and requires forensic triage per BOD 26-04 because patching does not remove backdoors already installed by attackers — organizations should follow Citrix's CTX694799 guidance to check for signs of compromise before and after patching (CISA KEV). As interim mitigations, restrict network access to management interfaces, implement network segmentation to limit exposure of NetScaler appliances to the internet, and monitor for anomalous DTLS traffic on UDP/443. If patching is not immediately possible, consider taking internet-facing NetScaler appliances offline until patched.

Community reactions

Citrix confirmed active exploitation in a security bulletin (CTX697096) published September 27–28, 2026, after security researchers (including watchTowr) had already publicly warned of unpatched zero-day exploitation over the preceding weekend — drawing criticism for delayed official disclosure (CyberScoop). CISA, NCSC (UK), ACSC (Australia), and multiple national CERTs issued urgent advisories urging immediate patching (NCSC UK, ACSC). Researcher Kevin Beaumont (@GossiTheDog) and others on social media highlighted the severity and the disclosure delay, with some administrators reportedly shutting down NetScaler appliances preemptively before official patches were available (BleepingComputer). Mandiant/Google, Rapid7, Sophos, Palo Alto Unit 42, and Sygnia all published threat intelligence reports confirming mass exploitation and custom malware deployment (Rapid7, Sophos, Unit 42).

Additional resources


Source: This report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88778HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88777HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88776HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88775HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88779HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
YesYesOct 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management