<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2026-88772 on Martin's Blog</title><link>https://mac.sploit.dk/tags/cve-2026-88772/</link><description>Recent content in CVE-2026-88772 on Martin's Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 29 Sep 2026 12:00:00 +0200</lastBuildDate><atom:link href="https://mac.sploit.dk/tags/cve-2026-88772/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-88772: Following a NetScaler DTLS Overflow Across Two Builds</title><link>https://mac.sploit.dk/blog/cve-2026-88772-netscaler-dtls-memory-overflow/</link><pubDate>Tue, 29 Sep 2026 12:00:00 +0200</pubDate><guid>https://mac.sploit.dk/blog/cve-2026-88772-netscaler-dtls-memory-overflow/</guid><description>&lt;p&gt;CVE-2026-88772 is a pre-authentication memory-overflow vulnerability in&#10;NetScaler ADC and NetScaler Gateway. Citrix says that it can lead to remote&#10;code execution or denial of service, requires DTLS to be enabled, and has been&#10;exploited in the wild.&lt;/p&gt;&#10;&lt;p&gt;The public advisory tells operators what to do: upgrade to a fixed build. It&#10;does not show the vulnerable copy or explain what changed. A&#10;&lt;a href="https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/"&gt;watchTowr analysis&lt;/a&gt;&#10;fills in that gap with a detailed account of DTLS record processing, a patched&#10;binary comparison, debugger observations, and a working exploit chain.&lt;/p&gt;&#10;&lt;p&gt;Comparing the local NetScaler 14.1 builds independently confirms the central&#10;root-cause claim. In build 73.30, the packet engine appends a linked chain of&#10;DTLS buffers to a fixed &lt;code&gt;0x8c00&lt;/code&gt;-byte global scratch area without checking the&#10;cumulative length. In build 73.37, the corresponding function tracks the&#10;remaining capacity and rejects an element before the copy that would exceed&#10;it.&lt;/p&gt;&#10;&lt;p&gt;That is strong static confirmation of the memory-corruption primitive and of&#10;the repair. It is not a local reproduction of a crash or remote code&#10;execution. No malicious packet was sent, DTLS was not enabled in the lab, and&#10;the public exploit was not run.&lt;/p&gt;</description></item></channel></rss>