Threat reportVulnerabilityTL-2026-2896

CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog

highACTIVE

CISA adds Citrix NetScaler SAML memory overflow DoS (TL-2026-2896) is a high-severity software vulnerability scored CVSS 8.7, first published 2026-10-04 and last reviewed 2026-10-05. It has no confirmed attribution, affects Cloud Software Group (Citrix) NetScaler ADC and NetScaler Gateway, references 1 CVE (CVE-2026-88779), maps to 8 MITRE ATT&CK techniques (T1059, T1059.004, T1105), and is covered by 9 detection rules and 24 indicators of compromise.

CVSS
8.7/10High
CVEs
1Referenced vulnerabilities
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2896

Threat ID
TL-2026-2896
Severity
HIGH
CVSS
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, technology, finance, health, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
24
Updates
2026-10-05 · 2 updates · revalidated 2× · latest source

How CISA adds Citrix NetScaler SAML memory overflow DoS works

CISA added CVE-2026-88779, a memory-buffer overflow (CWE-119) in Citrix NetScaler ADC and Gateway SAML authentication, to the Known Exploited Vulnerabilities Catalog on 2026-10-04. An unauthenticated remote attacker can repeatedly trigger the flaw to crash and reboot appliances configured as a SAML SP or IdP, causing sustained denial of service; exploitation in the wild is reported.

CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway. Cloud Software Group's bulletin CTX697174 rates it CVSS v4.0 8.7 (High), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N, i.e. network-reachable, no authentication, no user interaction, impact limited to availability. The appliance is only vulnerable when configured as a SAML Service Provider or SAML Identity Provider; Citrix tells customers to look for 'add authentication samlAction' or 'add authentication samlIdPProfile' in the running configuration. Credit is given to Bishop Fox and watchTowr.

Exploitation: secondary reporting (SecurityOnline, 2026-10-04) states attackers trigger the overflow repeatedly, causing appliance reboots and persistent denial of service on SAML-configured gateways; the same source suggests interim measures of applying Global Deny List signatures via NetScaler Console and firewalling attacking IP addresses. No threat actor is attributed and no network IOCs (IPs, domains, hashes) have been published. CISA's alert gives no CVSS, CWE or explicit due date; a secondary source (hol.org) reports a KEV due date of 2026-10-07 and catalog version 2026.10.04. CISA characterizes this class of flaw as a frequent attack vector for malicious cyber actors posing significant risk to the federal enterprise, and BOD 26-04 requires rapid remediation of KEV entries on publicly exposed assets.

Context: CVE-2026-88779 is a separate bulletin from the CVE-2026-88771 through CVE-2026-88778 batch (CTX697096), which was disclosed about 2026-09-27. Of that batch, CVE-2026-88771 (unauthenticated RCE via improper input validation, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 9.5) are confirmed exploited in the wild; secondary reporting says post-compromise activity there included webshells, credential theft and lateral movement. Those behaviors are NOT evidenced for CVE-2026-88779 itself, whose reported impact is DoS only. Defenders running NetScaler should treat both bulletins together because they affect the same product lines and branches.

MITRE ATT&CK techniques used in TL-2026-2896

Execution

T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter

Command and Control

T1105 Ingress Tool Transfer

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499 Endpoint Denial of Service; T1499.004 Application or System Exploitation

Persistence

T1505.003 Web Shell

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in CISA adds Citrix NetScaler SAML memory overflow DoS

  • Cloud Software Group (Citrix) — NetScaler ADC and NetScaler Gateway (SAML SP/IdP configured)
    Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; 14.1-FIPS before 14.1-73.41; 13.1-FIPS/NDcPP before 13.1-37.282
    Fixed in: 14.1-73.41 and later; 13.1-64.28 and later; 14.1-FIPS 14.1-73.41 and later; 13.1-FIPS/NDcPP 13.1-37.282 and later

Remediation for CISA adds Citrix NetScaler SAML memory overflow DoS

Patches

  • NetScaler ADC/Gateway 14.1-73.41 and later
  • NetScaler ADC/Gateway 13.1-64.28 and later
  • NetScaler ADC FIPS 14.1-73.41 and later
  • NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.282 and later

Immediate actions

  • Check running config for 'add authentication samlAction' / 'add authentication samlIdPProfile' to determine exposure
  • Upgrade to a fixed build
  • Apply Global Deny List signatures via NetScaler Console as an interim measure
  • Firewall block observed attacking IP addresses as interim protection
  • Monitor SAML-configured appliances for unexplained reboots and outages

Workarounds

  • No configuration workaround documented in the sources; appliances not configured as SAML SP or IdP are not vulnerable

Longer-term hardening

  • Track Citrix NetScaler bulletins CTX697096 and CTX697174 together and keep builds current
  • Retire NetScaler 13.1 builds past end of maintenance (2026-09-15) where possible

CVEs associated with CISA adds Citrix NetScaler SAML memory overflow DoS

CVE-2026-88779

Weaknesses (CWE) in CISA adds Citrix NetScaler SAML memory overflow DoS

CWE-119

Timeline of CISA adds Citrix NetScaler SAML memory overflow DoS

  • End of maintenance for the NetScaler 13.1 branch (per The Hacker News), relevant because 13.1 is among the affected branches
  • watchTowr's forensic findings on the sibling NetScaler zero-days CVE-2026-88771/88772 are first reported
  • Citrix bulletin CTX697096 discloses CVE-2026-88771 through CVE-2026-88778; 88771 and 88772 confirmed exploited (secondary sources give 2026-09-27 or 09-28)
  • Administrators (Reddit) and Kevin Beaumont report unexpected reboots of already-patched NetScaler appliances.
  • Citrix issues a security notice acknowledging a 'newly observed issue'; watchTowr Labs reproduces the vulnerability.
  • Cloud Software Group publishes CTX697174 for CVE-2026-88779 (SAML memory overflow DoS, CVSS v4.0 8.7) with fixed builds 14.1-73.41 and 13.1-64.28; credits Bishop Fox and watchTowr
  • Researchers report crafted authentication usernames with shell commands that download a payload from 213.209.159.55 (saved as /v and executed), plus a honeypot running a downloaded binary; BleepingComputer describes it as 'sprayed and prayed' mass exploitation.
  • CISA adds CVE-2026-88779 to the KEV Catalog; SecurityOnline reports active exploitation causing repeated appliance reboots on SAML-configured gateways
  • HKCERT publishes a High-risk bulletin on the Citrix NetScaler denial-of-service vulnerability, reporting exploitation in the wild.
  • KEV remediation due date per secondary source hol.org (not stated in CISA's alert)

Update history for TL-2026-2896

Sources cited for CISA adds Citrix NetScaler SAML memory overflow DoS

Detection coverage for TL-2026-2896

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2896 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats