Python 3 PoC for **[CVE-2026-88772]( — **Citrix NetScaler ADC** and **NetScaler Gateway**.
**CVE-2026-88772** — **Memory overflow** on **DTLS** (UDP TLS) handling can lead to **remote code execution** or **denial of service**. Exploitation requires **DTLS to be enabled**; on **Gateway**, DTLS is **on by default** for **VPN virtual servers** unless an administrator set **`-dtls OFF`**. DTLS-type vServers are also in scope.
| ADC / Gateway **14.1** | **14.1-73.37** and later |
| ADC / Gateway **13.1** | **13.1-64.23** and later |
| ADC **14.1 FIPS** | **14.1-73.37 FIPS** |
| ADC **13.1 FIPS / NDcPP** | **13.1.37.279** |
**CVSS 4.0:** **9.5 CRITICAL** (`AV:N/AC:H/PR:N/UI:N`, high C/I/A and subscores).
Citrix **CTX697096** (with **CVE-2026-88771** through **88778**) states **active exploitation** of **88771** and **88772** on unmitigated appliances. Prior August builds (**14.1-73.32**, **13.1-63.21**) do **not** fix this issue.
**PoC page:** [
Catalog: [
| **Vendor** | Citrix / Cloud Software Group |
| **Products** | **NetScaler ADC**, **NetScaler Gateway** |
| **Vector** | **Network**, **DTLS** (typically **UDP 443**) |
| **Mitigation** | Patch; or **disable DTLS** on VPN vServer |
This PoC **fingerprints** Gateway/ADC login surfaces, parses **build strings** when exposed, checks **UDP/443**, and optionally sends a **benign DTLS ClientHello** probe. It does **not** include the **memory overflow** trigger (weaponized in the wild).
python poc.py -u --mode check
python poc.py -u --mode check --dtls-probe
python poc.py -u --build 14.1-73.32 --mode check
python poc.py --list targets.example.txt --mode check -j 12
CVE-2026-88772 PoC: Citrix **NetScaler ADC/Gateway** **DTLS** memory overflow (**RCE/DoS**). Detects Gateway, build vs **14.1-73.37** / **13.1-64.23**, UDP/443 DTLS probe. [PoCbit](
**CVE-2026-88772:** NetScaler’da **DTLS** bellek taşması; varsayılan VPN DTLS ile **RCE/DoS**. Sıfır gün sömürüsü bildirildi. PoC: tespit + güvenli DTLS probe; overflow paketi yok.
Authorized testing and incident response only. Do not crash production appliances.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
