SecBoard
Zurück zur CVE-Übersicht

CVE-2026-88772

HIGH(8.1)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score56/100 — HOCH
  • CVSS 8.1 — Hoch
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

Erwähnungen (letzte 60 Tage)

Artikel

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

1.2%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

8.1

Technische Schwere

SecBoard-Einordnung

CVE-2026-88772 betrifft Citrix NetScaler ADC und Citrix NetScaler Gateway. Es handelt sich um eine Schwachstelle, die zu () oder Denial of Service (DoS) führen kann. Die genaue Art der Schwachstelle wird in der Beschreibung nicht näher spezifiziert, aber die potenziellen Auswirkungen sind erheblich. Betroffen sind spezifische Versionen vor 14.1-73.37 und 13.1-64.23 sowie FIPS- und NDcPP-Varianten. Diese Schwachstelle ist als kritisch einzustufen, da sie aktiv ausgenutzt wird und im KEV-Katalog aufgeführt ist. Die Möglichkeit zur stellt ein hohes Risiko für die Integrität und Vertraulichkeit der betroffenen Systeme dar. Ein Denial of Service kann die Verfügbarkeit kritischer Dienste beeinträchtigen. Security-Teams sollten umgehend alle betroffenen Citrix NetScaler ADC und Gateway Instanzen identifizieren und die verfügbaren Patches installieren. Aufgrund der aktiven Ausnutzung ist eine schnelle Reaktion unerlässlich, um potenzielle Angriffe zu verhindern. Eine Überwachung der Systeme auf ungewöhnliche Aktivitäten wird ebenfalls empfohlen.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Erkennung & Indikatoren

Ausnutzung

Aktiv ausgenutzt (CISA KEV). Citrix confirmed active exploitation of this vulnerability in zero-day attacks. The NCSC is working to understand the impact of these vulnerabilities on UK organisations. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

Behobene Versionen

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Threat-Hunting-Queries

Detection for memory overflow leading to RCE/DoS on Citrix NetScaler ADC/Gateway. Focus on unusual process behavior, crashes, or high resource usage.

Sentinel/Defender KQL

DeviceProcessEvents
| where FileName in~ ("nsd", "httpd", "sshd") // Common NetScaler processes
| where ProcessCommandLine contains "dtls" // If DTLS is a factor
| where InitiatingProcessFileName !in ("nsd", "httpd", "sshd") // Look for unusual parent processes
| where ProcessCommandLine has_any ("sh", "bash", "powershell", "cmd") // Shell execution indicators
| summarize count() by DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName
| where count_ > 5 // Adjust threshold as needed for your environment
| project DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, count_

Splunk SPL

index=your_netscaler_logs (process="nsd" OR process="httpd" OR process="sshd") (commandline=*dtls* OR commandline=*sh* OR commandline=*bash* OR commandline=*powershell* OR commandline=*cmd*)
| stats count by host, process, commandline, parent_process
| where count > 5

Sigma

title: Citrix NetScaler RCE/DoS via Memory Overflow
id: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
status: experimental
description: Detects potential remote code execution or denial of service attempts on Citrix NetScaler ADC/Gateway via memory overflow (CVE-2026-88772).
author: SecBoard
date: 2026/09/28
references:
  - https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
logsource:
  category: process_creation
  product: linux
tags:
  - attack.execution
  - cve.2026.88772
  - cisa_kev
detection:
  selection:
    Image|endswith:
      - '/nsd'
      - '/httpd'
      - '/sshd'
    CommandLine|contains:
      - 'dtls'
      - 'sh'
      - 'bash'
      - 'powershell'
      - 'cmd'
  condition: selection
falsepositives:
  - Legitimate administrative activities (requires tuning)
level: high

Elastic ES|QL

from process where process.executable in ("/usr/sbin/nsd", "/usr/sbin/httpd", "/usr/sbin/sshd") and (process.args contains "dtls" or process.args contains "sh" or process.args contains "bash" or process.args contains "powershell" or process.args contains "cmd")
| stats count() by host.name, process.executable, process.command_line, process.parent.executable
| where count > 5

SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Betroffene Produkte

  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

Referenzen