CVE-2026-88777
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
Erwähnungen (letzte 60 Tage)
EPSS-Score
0.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
Beschreibung
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service
Erkennung & Indikatoren
Ausnutzung
Citrix has confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 in the wild. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.
Behobene Versionen
- 14.1-73.37
- 13.1-64.23
- 14.1-73.37 FIPS
- 13.1.37.279 FIPS and NDcPP
Threat-Hunting-Queries
CVE-2026-88777 is a memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service (DoS). It affects Citrix NetScaler ADC and Citrix NetScaler Gateway deployments where an LB/CS or CGNAT-LSN/NAT64 with non-HTTP L7 protocol is enabled. Detection should focus on abnormal resource utilization (CPU, memory, network) or unexpected restarts/crashes of the NetScaler ser
Sentinel/Defender KQL
DeviceProcessEvents
| where FileName contains "netscaler" or FolderPath contains "netscaler"
| where ProcessCommandLine contains "non-HTTP L7 protocol" or InitiatingProcessCommandLine contains "non-HTTP L7 protocol" // Placeholder for specific process related to non-HTTP L7 protocol handling
| summarize count() by DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine
| extend Anomaly = "Potential memory overflow or DoS related to CVE-2026-88777"Splunk SPL
index=your_netscaler_logs (sourcetype=netscaler_adc OR sourcetype=netscaler_gateway) (error OR warning OR "denial of service" OR "memory overflow" OR "unpredictable behavior")
| where _raw like "*non-HTTP L7 protocol*"
| stats count by host, _raw
| rename _raw as "Log Message"
| table host, "Log Message", countSigma
title: Citrix NetScaler CVE-2026-88777 DoS
author: SecBoard
date: 2026/09/28
logsource:
product: netscaler
service: adc_gateway
detection:
selection:
- message|contains: ['memory overflow', 'denial of service', 'unpredictable behavior']
- message|contains: 'non-HTTP L7 protocol'
condition: selection
timeframe: 5m
level: highElastic ES|QL
from netscaler_logs
| where message : ("memory overflow" or "denial of service" or "unpredictable behavior") and message : "non-HTTP L7 protocol"
| stats count() by host, message
| sort by count descSecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- https://cert.europa.eu/publications/security-advisories/2026-014/
- https://www.cisa.gov/news-events/alerts/2026/09/27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway
Betroffene Produkte
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*