SecBoard
Zurück zur CVE-Übersicht

CVE-2026-88775

CRITICAL(9.8)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score30/100 — MITTEL
  • CVSS 9.8 — Kritisch

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.3%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.8

Technische Schwere

Beschreibung

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service

Erkennung & Indikatoren

Ausnutzung

Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.

Behobene Versionen

  • ADC: 14.1-73.37
  • ADC: 13.1-64.23
  • ADC: 14.1-73.37 FIPS
  • ADC: 13.1.37.279 FIPS and NDcPP
  • Gateway: 14.1-73.37
  • Gateway: 13.1-64.23

Threat-Hunting-Queries

CVE-2026-88775 is a memory overflow vulnerability that may result in unpredictable or erroneous behavior or denial of service. It affects deployments where a gateway or AAA vServer is configured. Detection should focus on abnormal process behavior or crashes related to NetScaler processes, especially when a gateway or AAA vServer is in use.

Sentinel/Defender KQL

DeviceProcessEvents
| where FileName contains "nsd" or FileName contains "httpd"
| where ProcessCommandLine contains "gateway" or ProcessCommandLine contains "aaa"
| where ProcessIntegrityLevel == "System" or ProcessIntegrityLevel == "High"
| summarize Count=count() by DeviceName, FileName, ProcessCommandLine
| where Count > 5 // Adjust threshold based on baseline
| project DeviceName, FileName, ProcessCommandLine, Count
// Further investigation for crashes or unexpected restarts of NetScaler services
| union DeviceProcessEvents
| where FileName contains "nsd" or FileName contains "httpd"
| where ActionType == "ProcessTerminated"
| where InitiatingProcessFileName !contains "update" and InitiatingProcessFileName !contains "patch"
| summarize Count=count() by DeviceName, FileName, InitiatingProcessFileName
| where Count > 1 // Look for multiple unexpected terminations
| project DeviceName, FileName, InitiatingProcessFileName, Count

Splunk SPL

(sourcetype=citrix:netscaler (process=nsd OR process=httpd) (commandline=*gateway* OR commandline=*aaa*)) OR (sourcetype=citrix:netscaler (process=nsd OR process=httpd) (status=terminated OR status=crashed) NOT (commandline=*update* OR commandline=*patch*))
| stats count by host, process, commandline
| where count > 5
| rename count as "Abnormal Process Count"
| table host, process, commandline, "Abnormal Process Count"

Sigma

title: Citrix NetScaler Memory Overflow DoS
id: 00000000-0000-0000-0000-0000000088775
status: experimental
description: Detects potential memory overflow leading to unpredictable behavior or DoS in Citrix NetScaler ADC/Gateway, specifically when gateway or AAA vServer is configured.
author: SecBoard
date: 2026/09/27
references:
  - https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
logsource:
  product: citrix
  service: netscaler
detection:
  selection_process_behavior:
    EventID: 1 # Placeholder for process creation/termination events, adjust based on actual logs
    Image|endswith:
      - '\nsd.exe'
      - '\httpd.exe'
    CommandLine|contains:
      - 'gateway'
      - 'aaa'
  selection_crash_behavior:
    EventID: 2 # Placeholder for crash/termination events, adjust based on actual logs
    Image|endswith:
      - '\nsd.exe'
      - '\httpd.exe'
    Status|contains:
      - 'terminated'
      - 'crashed'
    ParentImage|contains:
      - 'update' # Exclude planned updates
      - 'patch'
    ParentImage|contains:
      - 'upgrade'
  condition: 1 of selection_*
level: high

Elastic ES|QL

from logs-citrix.netscaler.*
| where process.name : ("nsd", "httpd")
| where process.args : ("*gateway*", "*aaa*")
| stats count() by host.name, process.name, process.args
| where count() > 5
| union
from logs-citrix.netscaler.*
| where process.name : ("nsd", "httpd")
| where event.action : ("process_terminated", "process_crashed")
| where not process.parent.name : ("update", "patch", "upgrade")
| stats count() by host.name, process.name, process.parent.name
| where count() > 1

SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Betroffene Produkte

  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

Referenzen