CVE-2026-88778
HIGH(7.5)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS 7.5 — Hoch
Erwähnungen (letzte 60 Tage)
EPSS-Score
0.4%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.5
Technische Schwere
Beschreibung
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
Erkennung & Indikatoren
Ausnutzung
In den geprüften Quellen nicht genannt
Behobene Versionen
- ADC: 14.1-73.37
- ADC: 13.1-64.23
- ADC: 14.1-73.37 FIPS
- ADC: 13.1.37.279 FIPS and NDcPP
- Gateway: 14.1-73.37
- Gateway: 13.1-64.23
Threat-Hunting-Queries
Detect TCP Initial Sequence Number (ISN) prediction attempts, which may indicate exploitation of CVE-2026-88778. This vulnerability affects deployments where a TCP configuration is enabled with Enhanced ISN Generation disabled.
Sentinel/Defender KQL
// This is a conceptual query as direct ISN prediction detection is complex and often requires deep packet inspection or specific NetScaler logs not detailed in the source.
// Look for unusual TCP session patterns, especially related to new connections or resets, that might indicate ISN prediction attempts.
// This query assumes logs from NetScaler or network devices are ingested and contain relevant TCP session information.
// Adjust 'YourNetScalerLogs' to your actual log table name.
YourNetScalerLogs
| where EventType == "TCP_SESSION_START" or EventType == "TCP_RESET"
| summarize SessionCount = count() by SourceIP, DestinationIP, DestinationPort, bin(TimeGenerated, 1m)
| where SessionCount > 5 // Example threshold for unusual activity, customize as needed
| project SourceIP, DestinationIP, DestinationPort, SessionCount, TimeGenerated
| order by TimeGenerated descSplunk SPL
# This is a conceptual query as direct ISN prediction detection is complex and often requires deep packet inspection or specific NetScaler logs not detailed in the source.
# Look for unusual TCP session patterns, especially related to new connections or resets, that might indicate ISN prediction attempts.
# This query assumes logs from NetScaler or network devices are ingested and contain relevant TCP session information.
# Adjust 'sourcetype=your_netscaler_logs' to your actual log sourcetype.
sourcetype=your_netscaler_logs (event_type="TCP_SESSION_START" OR event_type="TCP_RESET")
| stats count as SessionCount by src_ip, dest_ip, dest_port, _time span=1m
| where SessionCount > 5
| table _time, src_ip, dest_ip, dest_port, SessionCount
| sort -_timeSigma
title: Citrix NetScaler TCP ISN Prediction Attempt
id: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx # Generate a unique GUID
status: experimental
description: Detects potential attempts to exploit CVE-2026-88778 by observing unusual TCP session patterns indicative of ISN prediction.
references:
- https://www.cve.org/CVERecord?id=CVE-2026-88778
logsource:
product: netscaler
service: tcp_logs # Adjust service name based on actual log source
detection:
selection:
EventID: # Placeholder for relevant event ID if available
EventType: "TCP_SESSION_START" OR "TCP_RESET"
timeframe: 1m
condition: selection | stats count() by SourceIP, DestinationIP, DestinationPort | where count() > 5 # Example threshold
falsepositives:
- Legitimate network activity with high connection rates
level: mediumElastic ES|QL
// This is a conceptual query as direct ISN prediction detection is complex and often requires deep packet inspection or specific NetScaler logs not detailed in the source.
// Look for unusual TCP session patterns, especially related to new connections or resets, that might indicate ISN prediction attempts.
// This query assumes logs from NetScaler or network devices are ingested and contain relevant TCP session information.
// Adjust 'your_netscaler_logs' to your actual log index pattern.
FROM your_netscaler_logs
| WHERE event.type == "TCP_SESSION_START" OR event.type == "TCP_RESET"
| SUM(k = 1) BY source.ip, destination.ip, destination.port, RUNDOWN(event.ingested, 1m)
| WHERE k > 5 // Example threshold for unusual activity, customize as needed
| SELECT source.ip, destination.ip, destination.port, k AS session_count, RUNDOWN(event.ingested, 1m) AS time_window
| ORDER BY time_window DESCSecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway
- https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1235/
- https://cert.europa.eu/publications/security-advisories/2026-014/
Betroffene Produkte
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*