CVE-2026-88775
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
Erwähnungen (letzte 60 Tage)
EPSS-Score
0.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
Beschreibung
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service
Erkennung & Indikatoren
Ausnutzung
Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Behobene Versionen
- ADC: 14.1-73.37
- ADC: 13.1-64.23
- ADC: 14.1-73.37 FIPS
- ADC: 13.1.37.279 FIPS and NDcPP
- Gateway: 14.1-73.37
- Gateway: 13.1-64.23
Threat-Hunting-Queries
CVE-2026-88775 is a memory overflow vulnerability that may result in unpredictable or erroneous behavior or denial of service. It affects deployments where a gateway or AAA vServer is configured. Detection should focus on abnormal process behavior or crashes related to NetScaler processes, especially when a gateway or AAA vServer is in use.
Sentinel/Defender KQL
DeviceProcessEvents
| where FileName contains "nsd" or FileName contains "httpd"
| where ProcessCommandLine contains "gateway" or ProcessCommandLine contains "aaa"
| where ProcessIntegrityLevel == "System" or ProcessIntegrityLevel == "High"
| summarize Count=count() by DeviceName, FileName, ProcessCommandLine
| where Count > 5 // Adjust threshold based on baseline
| project DeviceName, FileName, ProcessCommandLine, Count
// Further investigation for crashes or unexpected restarts of NetScaler services
| union DeviceProcessEvents
| where FileName contains "nsd" or FileName contains "httpd"
| where ActionType == "ProcessTerminated"
| where InitiatingProcessFileName !contains "update" and InitiatingProcessFileName !contains "patch"
| summarize Count=count() by DeviceName, FileName, InitiatingProcessFileName
| where Count > 1 // Look for multiple unexpected terminations
| project DeviceName, FileName, InitiatingProcessFileName, CountSplunk SPL
(sourcetype=citrix:netscaler (process=nsd OR process=httpd) (commandline=*gateway* OR commandline=*aaa*)) OR (sourcetype=citrix:netscaler (process=nsd OR process=httpd) (status=terminated OR status=crashed) NOT (commandline=*update* OR commandline=*patch*))
| stats count by host, process, commandline
| where count > 5
| rename count as "Abnormal Process Count"
| table host, process, commandline, "Abnormal Process Count"Sigma
title: Citrix NetScaler Memory Overflow DoS
id: 00000000-0000-0000-0000-0000000088775
status: experimental
description: Detects potential memory overflow leading to unpredictable behavior or DoS in Citrix NetScaler ADC/Gateway, specifically when gateway or AAA vServer is configured.
author: SecBoard
date: 2026/09/27
references:
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
logsource:
product: citrix
service: netscaler
detection:
selection_process_behavior:
EventID: 1 # Placeholder for process creation/termination events, adjust based on actual logs
Image|endswith:
- '\nsd.exe'
- '\httpd.exe'
CommandLine|contains:
- 'gateway'
- 'aaa'
selection_crash_behavior:
EventID: 2 # Placeholder for crash/termination events, adjust based on actual logs
Image|endswith:
- '\nsd.exe'
- '\httpd.exe'
Status|contains:
- 'terminated'
- 'crashed'
ParentImage|contains:
- 'update' # Exclude planned updates
- 'patch'
ParentImage|contains:
- 'upgrade'
condition: 1 of selection_*
level: highElastic ES|QL
from logs-citrix.netscaler.*
| where process.name : ("nsd", "httpd")
| where process.args : ("*gateway*", "*aaa*")
| stats count() by host.name, process.name, process.args
| where count() > 5
| union
from logs-citrix.netscaler.*
| where process.name : ("nsd", "httpd")
| where event.action : ("process_terminated", "process_crashed")
| where not process.parent.name : ("update", "patch", "upgrade")
| stats count() by host.name, process.name, process.parent.name
| where count() > 1SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- https://cert.europa.eu/publications/security-advisories/2026-014/
- https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
Betroffene Produkte
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*