Detect Citrix NetScaler Memory Buffer Restriction Exploitation (CVE-2026-88779) in Google Chronicle
Detects exploitation attempts against CVE-2026-88779, an improper restriction of operations within the bounds of a memory buffer (CWE-119) vulnerability in Citrix NetScaler ADC and NetScaler Gateway. The flaw, reachable via SAML-related request processing on the appliance's authentication/VPN virtual servers, allows a remote attacker to trigger out-of-bounds memory operations leading to memory disclosure or remote code execution. CISA added this to the KEV catalog (BOD 26-04) after it was observed exploited in the wild as a zero-day. Detection focuses on anomalous NetScaler/Gateway access-log and web-proxy telemetry: malformed or oversized SAML POST bodies to authentication endpoints, abnormal response sizes indicating memory leakage, appliance process crashes/restarts, and post-exploitation shell or file-write activity on the NSPPE/management plane.
MITRE ATT&CK
YARA-L Detection Query
rule citrix_netscaler_cve_2026_88779_saml_exploit {
meta:
author = "argus"
description = "Oversized SAML POST and anomalous response to Citrix NetScaler/Gateway indicating CVE-2026-88779 exploitation"
severity = "CRITICAL"
cve = "CVE-2026-88779"
events:
$e.metadata.event_type = "NETWORK_HTTP"
(re.regex($e.principal.application, "(?i)netscaler|citrix") or re.regex($e.target.hostname, "(?i)netscaler|gateway"))
$e.network.http.method = "POST"
re.regex($e.target.url, "(?i)(/saml/|/cgi/samlauth|/nf/auth/doAuthentication|/vpn/)")
($e.network.sent_bytes > 65000 or $e.network.received_bytes > 1000000)
$ip = $e.principal.ip
match:
$ip over 10m
condition:
#e >= 3
} YARA-L 2.0 rule correlating oversized SAML authentication traffic to Citrix NetScaler/Gateway hosts, matching CVE-2026-88779 exploitation behavior.
Data Sources
Required Tables
False Positives & Tuning
- Large legitimate SAML assertions
- Appliance vulnerability scanning
- High-volume SSO from shared egress IPs
Other platforms for CVE-2026-88779
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Oversized SAML POST to NetScaler authentication endpoint
Expected signal: Proxy/NetScaler access log shows a POST to /cgi/samlauth with request size ~200KB from the test source IP.
- Test 2High-volume oversized SAML request burst
Expected signal: Five POST events to /saml/login from the same source IP within a 10-minute bin, each ~120KB.
- Test 3Simulated memory-disclosure large response
Expected signal: Proxy log records a POST to /saml/acs with a response size of ~1.2MB.
References (6)
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174
- https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2026-88779
- https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/
Response Playbook
Triage
- Confirm the destination host is a Citrix NetScaler ADC or Gateway appliance and identify its firmware build; cross-reference against the fixed builds listed in Citrix bulletin CTX697174.
- Review the flagged SAML/authentication requests: inspect request/response sizes, the raw SAMLRequest/SAMLResponse body (if captured), and whether responses contained unexpectedly large payloads suggesting memory disclosure.
- Correlate the source IP against the CISA KEV / threat-intel indicators and determine whether it is a known scanner, a corporate egress, or an unattributed external host.
- Check NetScaler ns.log and NSPPE logs around the event window for packet-engine crashes, core dumps, or process restarts that would indicate a successful out-of-bounds operation.
Containment
- If exploitation is confirmed or strongly suspected, place the NetScaler authentication/VPN virtual server in maintenance or block the offending source IP(s) at the perimeter firewall.
- Apply the Citrix patch from CTX697174 to affected builds immediately (KEV/BOD 26-04 mandates prompt remediation) and, per Citrix guidance, kill all active ICA/PCoIP and authentication sessions to invalidate any hijacked session tokens.
- Rotate the NetScaler SAML signing/encryption keys and any credentials or secrets that could have been exposed through memory disclosure.
Evidence Collection
- Capture a full NetScaler tech-support bundle (show techsupport) including ns.log, nsppe cores, and configuration, and preserve any core dump files before reboot/patching.
- Export the proxy/firewall/CEF records for all flagged source IPs over the preceding 7 days, preserving full request/response metadata and any PCAPs.
Escalation Criteria
- !Escalate to incident response immediately if any NSPPE crash/core dump coincides with the oversized requests or if post-exploitation shell, cron, or file-write activity is observed on the appliance.
- !Escalate if memory disclosure is evidenced by abnormally large responses returning configuration data, session tokens, or credential material, indicating confirmed compromise.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
NetScaler ns.log and NSPPE core dump files - >
SAML authentication request/response payloads in proxy/CEF logs - >
Appliance configuration (ns.conf) changes and newly created files under /var or /flash - >
Active and recently-terminated VPN/ICA session records
Tuning Guidance
Establish a per-IdP baseline for legitimate SAML assertion sizes to set realistic request/response byte thresholds — environments with many group claims may legitimately exceed 65KB. Whitelist known IdP and vulnerability-scanner source IPs. Prioritize alerts that pair oversized traffic with NSPPE crash/restart events, and reduce severity for isolated size anomalies without crash correlation.
Hunting Queries
Baselines SAML request/response sizes per source IP to surface outliers consistent with memory disclosure from CVE-2026-88779.
CommonSecurityLog | where DeviceProduct has_any ("NetScaler","Gateway") | where RequestURL has "saml" | summarize p95req=percentile(toint(column_ifexists("RequestSize",0)),95), maxresp=max(toint(column_ifexists("ResponseSize",0))) by SourceIP | where maxresp > 1000000 index=netscaler uri=*saml* | stats max(response_bytes) AS max_resp p95(request_bytes) AS p95_req by src_ip | where max_resp>1000000 Atomic Red Team Tests
Simulates an attacker sending an abnormally large SAML POST body to the NetScaler SAML authentication endpoint to trigger buffer-boundary handling (lab-only, non-weaponized).
Command
python3 -c "import urllib.request; data=('SAMLResponse='+'A'*200000).encode(); req=urllib.request.Request('https://netscaler.lab.local/cgi/samlauth', data=data, method='POST'); urllib.request.urlopen(req, timeout=5)" Cleanup
echo 'No persistent artifact created; clear test HTTP logs if required.' Expected Telemetry
Proxy/NetScaler access log shows a POST to /cgi/samlauth with request size ~200KB from the test source IP.
Expected Detection
The kql/spl rules fire on the oversized SAML request (req_bytes > 65000).
Sends multiple oversized SAML POSTs within a short window to emulate exploitation retries and trigger the per-source count threshold.
Command
for i in $(seq 1 5); do curl -k -s -o /dev/null -X POST --data "SAMLRequest=$(head -c 120000 /dev/zero | tr '\0' 'B')" https://netscaler.lab.local/saml/login; done Cleanup
echo 'No files created; rotate or clear lab access logs if desired.' Expected Telemetry
Five POST events to /saml/login from the same source IP within a 10-minute bin, each ~120KB.
Expected Detection
The summarize/stats threshold (Hits >= 3) in the kql/spl/sumo/chronicle rules triggers on the burst.
Stands up a mock NetScaler endpoint returning an oversized response to validate detection of abnormal response sizes indicative of memory leakage.
Command
python3 -c "import http.server,socketserver;\nclass H(http.server.BaseHTTPRequestHandler):\n def do_POST(self): self.send_response(200); self.end_headers(); self.wfile.write(b'X'*1200000)\nsocketserver.TCPServer(('127.0.0.1',8443),H).serve_forever()" & sleep 1; curl -s -o /dev/null -X POST --data 'SAMLResponse=test' http://127.0.0.1:8443/saml/acs Cleanup
pkill -f 'http.server' 2>/dev/null; echo 'Mock server stopped.' Expected Telemetry
Proxy log records a POST to /saml/acs with a response size of ~1.2MB.
Expected Detection
Rules keying on resp_bytes > 1000000 (max_resp threshold) fire on the oversized response.