CVE-2026-88776
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
Erwähnungen (letzte 60 Tage)
EPSS-Score
0.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
Beschreibung
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
Erkennung & Indikatoren
Ausnutzung
Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild.
Behobene Versionen
- 14.1-73.37
- 13.1-64.23
- 14.1-73.37 FIPS
- 13.1.37.279 FIPS and NDcPP
Threat-Hunting-Queries
CVE-2026-88776 is a memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service (DoS) when an LB vServer of type Oracle is configured. Detection should focus on abnormal behavior of the NetScaler ADC/Gateway, especially related to the Oracle LB vServer.
Sentinel/Defender KQL
DeviceProcessEvents
| where FileName contains "netscaler" or FolderPath contains "netscaler"
| where ProcessCommandLine contains "oracle" and InitiatingProcessCommandLine contains "lb vserver"
| summarize count() by DeviceName, InitiatingProcessCommandLine, ProcessCommandLine
| where count_ > 5 // Adjust threshold based on baseline
| project DeviceName, InitiatingProcessCommandLine, ProcessCommandLine, count_Splunk SPL
index=your_netscaler_logs (source="netscaler" OR sourcetype="citrix:netscaler") (process="oracle" AND process="lb vserver")
| stats count by host, process
| where count > 5Sigma
title: Citrix NetScaler ADC/Gateway Memory Overflow (CVE-2026-88776)
status: experimental
description: Detects potential exploitation of CVE-2026-88776 in Citrix NetScaler ADC/Gateway, indicated by unusual process activity related to Oracle LB vServers.
logsource:
product: citrix
service: netscaler
detection:
selection:
process_command_line|contains:
- 'oracle'
- 'lb vserver'
condition: selection
fields:
- host
- process_command_line
level: mediumElastic ES|QL
from logs-citrix.netscaler.*
| where process.command_line : "oracle" and process.command_line : "lb vserver"
| stats count() by host.name, process.command_line
| where count > 5SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- https://cert.europa.eu/publications/security-advisories/2026-014/
- https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
Betroffene Produkte
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*