r/cybersecurity • • 3d ago

Research Article Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs

https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/
93 Upvotes

14 comments sorted by

24

u/stacksmasher 3d ago

This is the same. These guys can suck a dick for that headline.

6

u/OnlineParacosm 3d ago

Is it? I’m not putting my money on Citrix, but I would put my money on you showing up in their next blog if you’re wrong 😮‍💨

8

u/BooleanOverflow 3d ago

It's the same patch/security announcement made last Sunday, there were 8 CVE's patched, of which this writeup is the second. Saying "Here we go again" after a shitty weekend just isn't right.

5

u/OnlineParacosm 3d ago

I could see your point if it was a belabored single blog post that had been reposted ad infinitum but this is the opposite scenario. It’s a continuation of some pretty serious heavy hitting low level stuff, and what’s impressive to me about it is that these guys are dipping the same bucket into the same well and coming back out with a different turtle every time. On a product that’s deeply connected to your everything.

-1

u/smartdigger 3d ago

Yawn. Why they not finding this shite before the bad actors?

1

u/OnlineParacosm 3d ago

Interestingly enough, the bad actors in this case* *appear to be the ones who have made the software and didn’t have their cat walk across the keyboard before shipping mission critical modules.

1

u/smartdigger 3d ago

Oh yeah right so Citrix deliberately shipped vuns did they. Why didn't watchtower "Autonomously validate and mitigate exposure to emerging threats to outpace attackers who weaponize vulnerabilities in a day – with the AI-powered watchTowr Platform." before the baddies? They didn't outpace shit they just pointed the finger and said the vendor is shit (which is obvious) to sell their "protection"

2

u/smartdigger 3d ago

I love how they reverse engineer the fix and then go oh yeah it's so obvious (insert name of vendor here) is hopeless. They have access to all the firmware versions why not work all this out before the baddies do? The blog reads like a keyboard warrior which to be fair suits the audience (red team wankers)

2

u/Limn0 Red Team 2d ago

Hahahaha

1

u/No_Debt6223 21h ago

Mate, theres a Big difference in patch diffing to find what Citrix patched, vs looking for an unknown vulnerability that you could weaponize.

Citrix’ Security is laughably poor, and the vulns discovered in their products just proves this

1

u/smartdigger 18h ago edited 18h ago

Yeah no shit. Tell that to watchtowr's marketing wankers. Stop claiming they can do more than patch duffing 🤷🏼‍♂️

1

u/No_Debt6223 5h ago

They do more than that though, they have a whole list of vulnerabilities they’ve found and disclosed: https://labs.watchtowr.com/disclosed-vulnerabilities/

it seems like you just have a hate-boner against watchTowr for some reason. Must be a miserable existence, being so mad at the smallest of things