CVE-2026-88779 Sumo Logic CSE · Sumo

Detect Citrix NetScaler Memory Buffer Restriction Exploitation (CVE-2026-88779) in Sumo Logic CSE

Detects exploitation attempts against CVE-2026-88779, an improper restriction of operations within the bounds of a memory buffer (CWE-119) vulnerability in Citrix NetScaler ADC and NetScaler Gateway. The flaw, reachable via SAML-related request processing on the appliance's authentication/VPN virtual servers, allows a remote attacker to trigger out-of-bounds memory operations leading to memory disclosure or remote code execution. CISA added this to the KEV catalog (BOD 26-04) after it was observed exploited in the wild as a zero-day. Detection focuses on anomalous NetScaler/Gateway access-log and web-proxy telemetry: malformed or oversized SAML POST bodies to authentication endpoints, abnormal response sizes indicating memory leakage, appliance process crashes/restarts, and post-exploitation shell or file-write activity on the NSPPE/management plane.

MITRE ATT&CK

Tactic
Initial Access Execution Privilege Escalation

Sumo Detection Query

Sumo Logic CSE (Sumo)
sql
_sourceCategory=*netscaler* OR _sourceCategory=*citrix*
| where (method = "POST")
| where (url matches "*/saml/*" or url matches "*/cgi/samlauth*" or url matches "*/nf/auth/doAuthentication*" or url matches "*/vpn/*")
| parse "req_bytes=*" as req_bytes nodrop | parse "resp_bytes=*" as resp_bytes nodrop
| where (num(req_bytes) > 65000 or num(resp_bytes) > 1000000)
| count as hits, max(num(req_bytes)) as max_req, max(num(resp_bytes)) as max_resp by src_ip, dest_host
| where hits >= 3 or max_resp > 1000000
| sort by max_resp desc
high severity medium confidence

Detects oversized SAML POSTs and anomalous response sizes to Citrix NetScaler/Gateway endpoints characteristic of CVE-2026-88779 memory-buffer abuse.

Data Sources

Citrix NetScaler syslog collectorWeb proxy

Required Tables

_sourceCategory=netscaler

False Positives & Tuning

  • Federated SSO with large attribute payloads
  • Authorized appliance scanning
  • Shared NAT egress inflating per-source request counts

Other platforms for CVE-2026-88779


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Oversized SAML POST to NetScaler authentication endpoint

    Expected signal: Proxy/NetScaler access log shows a POST to /cgi/samlauth with request size ~200KB from the test source IP.

  2. Test 2High-volume oversized SAML request burst

    Expected signal: Five POST events to /saml/login from the same source IP within a 10-minute bin, each ~120KB.

  3. Test 3Simulated memory-disclosure large response

    Expected signal: Proxy log records a POST to /saml/acs with a response size of ~1.2MB.


Response Playbook

Triage

  1. Confirm the destination host is a Citrix NetScaler ADC or Gateway appliance and identify its firmware build; cross-reference against the fixed builds listed in Citrix bulletin CTX697174.
  2. Review the flagged SAML/authentication requests: inspect request/response sizes, the raw SAMLRequest/SAMLResponse body (if captured), and whether responses contained unexpectedly large payloads suggesting memory disclosure.
  3. Correlate the source IP against the CISA KEV / threat-intel indicators and determine whether it is a known scanner, a corporate egress, or an unattributed external host.
  4. Check NetScaler ns.log and NSPPE logs around the event window for packet-engine crashes, core dumps, or process restarts that would indicate a successful out-of-bounds operation.

Containment

  1. If exploitation is confirmed or strongly suspected, place the NetScaler authentication/VPN virtual server in maintenance or block the offending source IP(s) at the perimeter firewall.
  2. Apply the Citrix patch from CTX697174 to affected builds immediately (KEV/BOD 26-04 mandates prompt remediation) and, per Citrix guidance, kill all active ICA/PCoIP and authentication sessions to invalidate any hijacked session tokens.
  3. Rotate the NetScaler SAML signing/encryption keys and any credentials or secrets that could have been exposed through memory disclosure.

Evidence Collection

  1. Capture a full NetScaler tech-support bundle (show techsupport) including ns.log, nsppe cores, and configuration, and preserve any core dump files before reboot/patching.
  2. Export the proxy/firewall/CEF records for all flagged source IPs over the preceding 7 days, preserving full request/response metadata and any PCAPs.

Escalation Criteria

  • !Escalate to incident response immediately if any NSPPE crash/core dump coincides with the oversized requests or if post-exploitation shell, cron, or file-write activity is observed on the appliance.
  • !Escalate if memory disclosure is evidenced by abnormally large responses returning configuration data, session tokens, or credential material, indicating confirmed compromise.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >NetScaler ns.log and NSPPE core dump files
  • >SAML authentication request/response payloads in proxy/CEF logs
  • >Appliance configuration (ns.conf) changes and newly created files under /var or /flash
  • >Active and recently-terminated VPN/ICA session records

Tuning Guidance

Establish a per-IdP baseline for legitimate SAML assertion sizes to set realistic request/response byte thresholds — environments with many group claims may legitimately exceed 65KB. Whitelist known IdP and vulnerability-scanner source IPs. Prioritize alerts that pair oversized traffic with NSPPE crash/restart events, and reduce severity for isolated size anomalies without crash correlation.


Hunting Queries

Baselines SAML request/response sizes per source IP to surface outliers consistent with memory disclosure from CVE-2026-88779.

Hunting — KQL
kql
CommonSecurityLog | where DeviceProduct has_any ("NetScaler","Gateway") | where RequestURL has "saml" | summarize p95req=percentile(toint(column_ifexists("RequestSize",0)),95), maxresp=max(toint(column_ifexists("ResponseSize",0))) by SourceIP | where maxresp > 1000000
Hunting — SPL
spl
index=netscaler uri=*saml* | stats max(response_bytes) AS max_resp p95(request_bytes) AS p95_req by src_ip | where max_resp>1000000

Atomic Red Team Tests

Test 1 Oversized SAML POST to NetScaler authentication endpoint
linux

Simulates an attacker sending an abnormally large SAML POST body to the NetScaler SAML authentication endpoint to trigger buffer-boundary handling (lab-only, non-weaponized).

Command

bash
python3 -c "import urllib.request; data=('SAMLResponse='+'A'*200000).encode(); req=urllib.request.Request('https://netscaler.lab.local/cgi/samlauth', data=data, method='POST'); urllib.request.urlopen(req, timeout=5)"

Cleanup

bash
echo 'No persistent artifact created; clear test HTTP logs if required.'

Expected Telemetry

Proxy/NetScaler access log shows a POST to /cgi/samlauth with request size ~200KB from the test source IP.

Expected Detection

The kql/spl rules fire on the oversized SAML request (req_bytes > 65000).

Test 2 High-volume oversized SAML request burst
linux

Sends multiple oversized SAML POSTs within a short window to emulate exploitation retries and trigger the per-source count threshold.

Command

bash
for i in $(seq 1 5); do curl -k -s -o /dev/null -X POST --data "SAMLRequest=$(head -c 120000 /dev/zero | tr '\0' 'B')" https://netscaler.lab.local/saml/login; done

Cleanup

bash
echo 'No files created; rotate or clear lab access logs if desired.'

Expected Telemetry

Five POST events to /saml/login from the same source IP within a 10-minute bin, each ~120KB.

Expected Detection

The summarize/stats threshold (Hits >= 3) in the kql/spl/sumo/chronicle rules triggers on the burst.

Test 3 Simulated memory-disclosure large response
linux

Stands up a mock NetScaler endpoint returning an oversized response to validate detection of abnormal response sizes indicative of memory leakage.

Command

bash
python3 -c "import http.server,socketserver;\nclass H(http.server.BaseHTTPRequestHandler):\n def do_POST(self): self.send_response(200); self.end_headers(); self.wfile.write(b'X'*1200000)\nsocketserver.TCPServer(('127.0.0.1',8443),H).serve_forever()" & sleep 1; curl -s -o /dev/null -X POST --data 'SAMLResponse=test' http://127.0.0.1:8443/saml/acs

Cleanup

bash
pkill -f 'http.server' 2>/dev/null; echo 'Mock server stopped.'

Expected Telemetry

Proxy log records a POST to /saml/acs with a response size of ~1.2MB.

Expected Detection

Rules keying on resp_bytes > 1000000 (max_resp threshold) fire on the oversized response.

Related Detections