CVE-2026-88771
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
1.0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-88771 betrifft Citrix NetScaler ADC und Citrix NetScaler Gateway und ist eine Schwachstelle aufgrund unsachgemäßer Eingabevalidierung. Diese ermöglicht es einem nicht authentifizierten Angreifer, beliebige Befehle auszuführen. Die Kompromittierung der Systeme kann weitreichende Auswirkungen auf die Verfügbarkeit und Integrität der betroffenen Infrastruktur haben.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Erkennung & Indikatoren
Ausnutzung
Aktiv ausgenutzt (CISA KEV). Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild. The NCSC is working to understand the impact of these vulnerabilities on UK organisations. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Behobene Versionen
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
- Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP
Threat-Hunting-Queries
This query looks for unusual process execution patterns that might indicate arbitrary command execution on a NetScaler ADC or Gateway. Specific process names and arguments may need adjustment based on the environment.
Sentinel/Defender KQL
DeviceProcessEvents
| where FileName in~ ("sh", "bash", "perl", "python", "php", "wget", "curl", "nc", "ncat", "powershell.exe", "cmd.exe")
| where InitiatingProcessFileName in~ ("httpd", "nginx", "java", "tomcat") or InitiatingProcessCommandLine contains "netscaler"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, FolderPath, RemoteIP, RemoteUrl
| summarize count() by DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine
| where count_ > 5 // Adjust threshold as needed to reduce false positivesSplunk SPL
(sourcetype=linux_audit OR sourcetype=syslog OR sourcetype=windows_security) (process="sh" OR process="bash" OR process="perl" OR process="python" OR process="php" OR process="wget" OR process="curl" OR process="nc" OR process="ncat" OR process="powershell.exe" OR process="cmd.exe") (parent_process="httpd" OR parent_process="nginx" OR parent_process="java" OR parent_process="tomcat" OR command_line=*netscaler*)
| stats count by host, parent_process, process, command_line
| where count > 5Sigma
title: Citrix NetScaler RCE Attempt
id: 00000000-0000-0000-0000-000000000001
status: experimental
description: Detects potential arbitrary command execution on Citrix NetScaler ADC/Gateway via CVE-2026-88771.
author: SecBoard
date: 2026/09/28
logsource:
category: process_creation
product: linux
service: auditd
detection:
selection:
ParentImage|endswith:
- '\httpd'
- '\nginx'
- '\java'
- '\tomcat'
Image|endswith:
- '\sh'
- '\bash'
- '\perl'
- '\python'
- '\php'
- '\wget'
- '\curl'
- '\nc'
- '\ncat'
- '\powershell.exe'
- '\cmd.exe'
condition: selection
falsepositives:
- Legitimate administrative scripts (requires tuning)
level: highElastic ES|QL
from process.start
| where process.parent.name in ("httpd", "nginx", "java", "tomcat") or process.parent.command_line : "*netscaler*"
| where process.name in ("sh", "bash", "perl", "python", "php", "wget", "curl", "nc", "ncat", "powershell.exe", "cmd.exe")
| summarize count() by host.name, process.parent.name, process.name, process.command_line
| where count > 5SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- https://www.securityweek.com/citrix-confirms-2-netscaler-zero-days-after-admins-pulled-the-plug/
- https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html
- https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771
Betroffene Produkte
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*