SecBoard
Zurück zur CVE-Übersicht

CVE-2026-88776

CRITICAL(9.8)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score30/100 — MITTEL
  • CVSS 9.8 — Kritisch

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.3%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.8

Technische Schwere

Beschreibung

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23  leading to unpredictable or erroneous behavior or Denial of Service

Erkennung & Indikatoren

Ausnutzung

Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild.

Behobene Versionen

  • 14.1-73.37
  • 13.1-64.23
  • 14.1-73.37 FIPS
  • 13.1.37.279 FIPS and NDcPP

Threat-Hunting-Queries

CVE-2026-88776 is a memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service (DoS) when an LB vServer of type Oracle is configured. Detection should focus on abnormal behavior of the NetScaler ADC/Gateway, especially related to the Oracle LB vServer.

Sentinel/Defender KQL

DeviceProcessEvents
| where FileName contains "netscaler" or FolderPath contains "netscaler"
| where ProcessCommandLine contains "oracle" and InitiatingProcessCommandLine contains "lb vserver"
| summarize count() by DeviceName, InitiatingProcessCommandLine, ProcessCommandLine
| where count_ > 5 // Adjust threshold based on baseline
| project DeviceName, InitiatingProcessCommandLine, ProcessCommandLine, count_

Splunk SPL

index=your_netscaler_logs (source="netscaler" OR sourcetype="citrix:netscaler") (process="oracle" AND process="lb vserver")
| stats count by host, process
| where count > 5

Sigma

title: Citrix NetScaler ADC/Gateway Memory Overflow (CVE-2026-88776)
status: experimental
description: Detects potential exploitation of CVE-2026-88776 in Citrix NetScaler ADC/Gateway, indicated by unusual process activity related to Oracle LB vServers.
logsource:
  product: citrix
  service: netscaler
detection:
  selection:
    process_command_line|contains: 
      - 'oracle'
      - 'lb vserver'
  condition: selection
fields:
  - host
  - process_command_line
level: medium

Elastic ES|QL

from logs-citrix.netscaler.*
| where process.command_line : "oracle" and process.command_line : "lb vserver"
| stats count() by host.name, process.command_line
| where count > 5

SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Betroffene Produkte

  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
  • cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*

Referenzen