SecBoard
Zurück zur CVE-Übersicht

CVE-2026-88771

CRITICAL(9.8)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score60/100 — HOCH
  • CVSS 9.8 — Kritisch
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

Erwähnungen (letzte 60 Tage)

Artikel

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

1.0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.8

Technische Schwere

SecBoard-Einordnung

CVE-2026-88771 betrifft Citrix NetScaler ADC und Citrix NetScaler Gateway und ist eine Schwachstelle aufgrund unsachgemäßer Eingabevalidierung. Diese ermöglicht es einem nicht authentifizierten Angreifer, beliebige Befehle auszuführen. Die Kompromittierung der Systeme kann weitreichende Auswirkungen auf die Verfügbarkeit und Integrität der betroffenen Infrastruktur haben.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Erkennung & Indikatoren

Ausnutzung

Aktiv ausgenutzt (CISA KEV). Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild. The NCSC is working to understand the impact of these vulnerabilities on UK organisations. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

Behobene Versionen

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Threat-Hunting-Queries

This query looks for unusual process execution patterns that might indicate arbitrary command execution on a NetScaler ADC or Gateway. Specific process names and arguments may need adjustment based on the environment.

Sentinel/Defender KQL

DeviceProcessEvents
| where FileName in~ ("sh", "bash", "perl", "python", "php", "wget", "curl", "nc", "ncat", "powershell.exe", "cmd.exe")
| where InitiatingProcessFileName in~ ("httpd", "nginx", "java", "tomcat") or InitiatingProcessCommandLine contains "netscaler"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, FolderPath, RemoteIP, RemoteUrl
| summarize count() by DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine
| where count_ > 5 // Adjust threshold as needed to reduce false positives

Splunk SPL

(sourcetype=linux_audit OR sourcetype=syslog OR sourcetype=windows_security) (process="sh" OR process="bash" OR process="perl" OR process="python" OR process="php" OR process="wget" OR process="curl" OR process="nc" OR process="ncat" OR process="powershell.exe" OR process="cmd.exe") (parent_process="httpd" OR parent_process="nginx" OR parent_process="java" OR parent_process="tomcat" OR command_line=*netscaler*)
| stats count by host, parent_process, process, command_line
| where count > 5

Sigma

title: Citrix NetScaler RCE Attempt
id: 00000000-0000-0000-0000-000000000001
status: experimental
description: Detects potential arbitrary command execution on Citrix NetScaler ADC/Gateway via CVE-2026-88771.
author: SecBoard
date: 2026/09/28
logsource:
  category: process_creation
  product: linux
  service: auditd
detection:
  selection:
    ParentImage|endswith:
      - '\httpd'
      - '\nginx'
      - '\java'
      - '\tomcat'
    Image|endswith:
      - '\sh'
      - '\bash'
      - '\perl'
      - '\python'
      - '\php'
      - '\wget'
      - '\curl'
      - '\nc'
      - '\ncat'
      - '\powershell.exe'
      - '\cmd.exe'
  condition: selection
falsepositives:
  - Legitimate administrative scripts (requires tuning)
level: high

Elastic ES|QL

from process.start
| where process.parent.name in ("httpd", "nginx", "java", "tomcat") or process.parent.command_line : "*netscaler*"
| where process.name in ("sh", "bash", "perl", "python", "php", "wget", "curl", "nc", "ncat", "powershell.exe", "cmd.exe")
| summarize count() by host.name, process.parent.name, process.name, process.command_line
| where count > 5

SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Betroffene Produkte

  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

Referenzen