CVE-2026-88771 Splunk · SPL

Detect Citrix NetScaler Improper Input Validation Exploitation (CVE-2026-88771) in Splunk

Detects exploitation attempts and post-exploitation indicators for CVE-2026-88771, an improper input validation (memory corruption, CWE-119) vulnerability in Citrix NetScaler ADC and NetScaler Gateway. Listed in CISA KEV and covered by CISA BOD 26-04 as an actively exploited zero-day. Exploitation typically manifests as anomalous requests to NetScaler management or VPN/AAA endpoints, unexpected process crashes on the appliance (nsppe/httpd), and subsequent unauthorized session creation or webshell activity. This detection correlates suspicious HTTP request patterns against NetScaler-facing surfaces, appliance error/crash telemetry, and follow-on webshell/reverse-shell behavior.

MITRE ATT&CK

Tactic
Initial Access Execution

SPL Detection Query

Splunk (SPL)
spl
index=citrix (sourcetype="citrix:netscaler:syslog" OR sourcetype="citrix:netscaler:cef" OR vendor="Citrix")
| eval uri=coalesce(url, uri_path, cs_uri_stem)
| where match(uri, "(?i)(/nf/auth|/vpn/|/gwtest/|/cgi/|/pcidss/report|/menu/neo|/menu/stapcss|/deviceinfo)")
| eval uri_len=len(uri)
| where uri_len>512 OR match(uri, "(?i)(%00|\.\./|\.\.%2f)") OR NOT match(http_user_agent, "(?i)(Mozilla|NetScaler)")
| stats count values(uri) as uris values(http_method) as methods dc(uri) as distinct_uris by src_ip dest_ip sourcetype
| where count>5
| sort - count
critical severity medium confidence

Splunk correlation over NetScaler syslog/CEF for malformed or oversized requests to exploitable endpoints tied to CVE-2026-88771.

Data Sources

Citrix NetScaler CEF/SyslogNetwork Firewall Logs

Required Sourcetypes

citrix:netscaler:syslogcitrix:netscaler:cef

False Positives & Tuning

  • Authorized scanners producing malformed request bursts
  • High-volume legitimate VPN authentication traffic during peak hours
  • Automated monitoring hitting management endpoints

Other platforms for CVE-2026-88771


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Oversized malformed request to NetScaler VPN endpoint

    Expected signal: Firewall/proxy log entry showing a >512-byte URI to /vpn/ with path traversal from the test source IP

  2. Test 2Null-byte injection against management endpoint

    Expected signal: NetScaler syslog/CEF record with %00 in the requested URL

  3. Test 3Burst of anomalous requests to NetScaler endpoints

    Expected signal: 10 request records within a 10-minute window from a single source with non-standard user agent


Response Playbook

Triage

  1. Confirm the destination IP/hostname is a Citrix NetScaler ADC or Gateway appliance and identify its firmware build to determine whether it is a version affected by CVE-2026-88771.
  2. Review the flagged requests: inspect URI length, encoding anomalies (%00, ../), request bodies, and source IP reputation to distinguish exploitation from scanning.
  3. Check NetScaler ns.log and appliance crash/core dumps (nsppe/httpd) around the alert window for signs of memory corruption or process restarts.
  4. Correlate the source IP against known-bad indicators, threat intel feeds, and any prior authentication or session-creation events from the same source.

Containment

  1. Per CISA BOD 26-04 and Citrix guidance (CTX697096), apply the vendor fix immediately or take the NetScaler appliance offline if unpatched and actively targeted.
  2. Block the offending source IP(s) at the perimeter firewall and terminate any active ICA/VPN sessions associated with them.
  3. Rotate all NetScaler secrets: management credentials, session keys, and any certificates, following CTX694799 compromise-recovery steps.

Evidence Collection

  1. Capture the NetScaler ns.log, newnslog, and any core/crash dumps for forensic analysis before rebooting the appliance.
  2. Export the full HTTP request/response records for the flagged transactions from firewall/proxy/WAF logs.
  3. Snapshot the appliance configuration (ns.conf) and running sessions to identify unauthorized changes or persistence.

Escalation Criteria

  • !Escalate to incident response immediately if appliance process crashes coincide with malformed requests, indicating successful memory corruption.
  • !Escalate if unauthorized session creation, new admin accounts, config changes, or webshell files are found following the suspicious requests.
  • !Escalate to leadership and CISA reporting channels given KEV/BOD 26-04 status if exploitation is confirmed against an internet-facing appliance.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >NetScaler ns.log / newnslog entries showing process restarts or malformed request handling
  • >Appliance core/crash dumps for nsppe and httpd processes
  • >Unexpected files under /var/netscaler/ or /netscaler/ (potential webshells) and modified ns.conf

Tuning Guidance

Baseline normal VPN/AAA request lengths for your environment before enforcing the 512-byte URI threshold — some SSO/SAML flows legitimately produce long query strings. Whitelist authorized scanner and monitoring source IPs. Tighten the endpoint list to only those NetScaler features you have enabled (e.g., remove /pcidss/report if PCI reporting is unused) to reduce noise, and pair the network signal with appliance process/crash telemetry to raise confidence.


Hunting Queries

Hunts for post-exploitation webshell access patterns against NetScaler file paths and script extensions.

Hunting — KQL
kql
CommonSecurityLog | where DeviceProduct has_any ("NetScaler", "ADC") | where RequestURL has_any (".php", ".pl", "/netscaler/") | summarize count() by SourceIP, RequestURL, bin(TimeGenerated, 1h) | where count_ > 0
Hunting — SPL
spl
index=citrix sourcetype=citrix:netscaler:* | regex uri="(?i)(\.php|\.pl|/netscaler/)" | stats count by src_ip, uri

Atomic Red Team Tests

Test 1 Oversized malformed request to NetScaler VPN endpoint
linux

Simulates an exploitation probe sending an oversized, malformed URI to a NetScaler VPN/AAA endpoint (lab appliance only).

Command

bash
curl -sk "https://netscaler-lab.example.local/vpn/../vpns/cfg/smb.conf?$(python3 -c 'print("A"*600)')" -A "exploit-probe" -o /dev/null

Cleanup

bash
echo 'No local artifacts to clean; review lab appliance ns.log'

Expected Telemetry

Firewall/proxy log entry showing a >512-byte URI to /vpn/ with path traversal from the test source IP

Expected Detection

KQL/SPL correlation fires on oversized URI + traversal to NetScaler endpoint

Test 2 Null-byte injection against management endpoint
linux

Sends a request containing an encoded null byte to a NetScaler management URL to simulate input-validation abuse.

Command

bash
curl -sk "https://netscaler-lab.example.local/menu/neo?arg=%00%00%00" -A "scanner" -o /dev/null

Cleanup

bash
echo 'No local artifacts; rotate lab appliance test session'

Expected Telemetry

NetScaler syslog/CEF record with %00 in the requested URL

Expected Detection

Detection matches on %00 encoding pattern against management endpoint

Test 3 Burst of anomalous requests to NetScaler endpoints
linux

Generates a burst of requests to multiple NetScaler endpoints with a non-browser user agent to trigger volume-based correlation.

Command

bash
for i in $(seq 1 10); do curl -sk "https://netscaler-lab.example.local/deviceinfo" -A "custom-agent" -o /dev/null; done

Cleanup

bash
echo 'No local artifacts to clean'

Expected Telemetry

10 request records within a 10-minute window from a single source with non-standard user agent

Expected Detection

Correlation fires when count of anomalous requests exceeds the threshold (>5)

Related Detections