Threat reportVulnerabilityTL-2026-2896
CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog
CISA adds Citrix NetScaler SAML memory overflow DoS (TL-2026-2896) is a high-severity software vulnerability scored CVSS 8.7, first published 2026-10-04 and last reviewed 2026-10-05. It has no confirmed attribution, affects Cloud Software Group (Citrix) NetScaler ADC and NetScaler Gateway, references 1 CVE (CVE-2026-88779), maps to 8 MITRE ATT&CK techniques (T1059, T1059.004, T1105), and is covered by 9 detection rules and 24 indicators of compromise.
- CVSS
- 8.7/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2896
- Threat ID
- TL-2026-2896
- Severity
- HIGH
- CVSS
- 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, technology, finance, health, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
- Updates
- 2026-10-05 · 2 updates · revalidated 2× · latest source
How CISA adds Citrix NetScaler SAML memory overflow DoS works
CISA added CVE-2026-88779, a memory-buffer overflow (CWE-119) in Citrix NetScaler ADC and Gateway SAML authentication, to the Known Exploited Vulnerabilities Catalog on 2026-10-04. An unauthenticated remote attacker can repeatedly trigger the flaw to crash and reboot appliances configured as a SAML SP or IdP, causing sustained denial of service; exploitation in the wild is reported.
CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway. Cloud Software Group's bulletin CTX697174 rates it CVSS v4.0 8.7 (High), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N, i.e. network-reachable, no authentication, no user interaction, impact limited to availability. The appliance is only vulnerable when configured as a SAML Service Provider or SAML Identity Provider; Citrix tells customers to look for 'add authentication samlAction' or 'add authentication samlIdPProfile' in the running configuration. Credit is given to Bishop Fox and watchTowr.
Exploitation: secondary reporting (SecurityOnline, 2026-10-04) states attackers trigger the overflow repeatedly, causing appliance reboots and persistent denial of service on SAML-configured gateways; the same source suggests interim measures of applying Global Deny List signatures via NetScaler Console and firewalling attacking IP addresses. No threat actor is attributed and no network IOCs (IPs, domains, hashes) have been published. CISA's alert gives no CVSS, CWE or explicit due date; a secondary source (hol.org) reports a KEV due date of 2026-10-07 and catalog version 2026.10.04. CISA characterizes this class of flaw as a frequent attack vector for malicious cyber actors posing significant risk to the federal enterprise, and BOD 26-04 requires rapid remediation of KEV entries on publicly exposed assets.
Context: CVE-2026-88779 is a separate bulletin from the CVE-2026-88771 through CVE-2026-88778 batch (CTX697096), which was disclosed about 2026-09-27. Of that batch, CVE-2026-88771 (unauthenticated RCE via improper input validation, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 9.5) are confirmed exploited in the wild; secondary reporting says post-compromise activity there included webshells, credential theft and lateral movement. Those behaviors are NOT evidenced for CVE-2026-88779 itself, whose reported impact is DoS only. Defenders running NetScaler should treat both bulletins together because they affect the same product lines and branches.
MITRE ATT&CK techniques used in TL-2026-2896
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499 Endpoint Denial of Service; T1499.004 Application or System Exploitation
Persistence
Reconnaissance
Affected products and versions in CISA adds Citrix NetScaler SAML memory overflow DoS
- Cloud Software Group (Citrix) — NetScaler ADC and NetScaler Gateway (SAML SP/IdP configured)
Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; 14.1-FIPS before 14.1-73.41; 13.1-FIPS/NDcPP before 13.1-37.282
Fixed in: 14.1-73.41 and later; 13.1-64.28 and later; 14.1-FIPS 14.1-73.41 and later; 13.1-FIPS/NDcPP 13.1-37.282 and later
Remediation for CISA adds Citrix NetScaler SAML memory overflow DoS
Patches
- NetScaler ADC/Gateway 14.1-73.41 and later
- NetScaler ADC/Gateway 13.1-64.28 and later
- NetScaler ADC FIPS 14.1-73.41 and later
- NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.282 and later
Immediate actions
- Check running config for 'add authentication samlAction' / 'add authentication samlIdPProfile' to determine exposure
- Upgrade to a fixed build
- Apply Global Deny List signatures via NetScaler Console as an interim measure
- Firewall block observed attacking IP addresses as interim protection
- Monitor SAML-configured appliances for unexplained reboots and outages
Workarounds
- No configuration workaround documented in the sources; appliances not configured as SAML SP or IdP are not vulnerable
Longer-term hardening
- Track Citrix NetScaler bulletins CTX697096 and CTX697174 together and keep builds current
- Retire NetScaler 13.1 builds past end of maintenance (2026-09-15) where possible
CVEs associated with CISA adds Citrix NetScaler SAML memory overflow DoS
Weaknesses (CWE) in CISA adds Citrix NetScaler SAML memory overflow DoS
Timeline of CISA adds Citrix NetScaler SAML memory overflow DoS
- End of maintenance for the NetScaler 13.1 branch (per The Hacker News), relevant because 13.1 is among the affected branches
- watchTowr's forensic findings on the sibling NetScaler zero-days CVE-2026-88771/88772 are first reported
- Citrix bulletin CTX697096 discloses CVE-2026-88771 through CVE-2026-88778; 88771 and 88772 confirmed exploited (secondary sources give 2026-09-27 or 09-28)
- Administrators (Reddit) and Kevin Beaumont report unexpected reboots of already-patched NetScaler appliances.
- Citrix issues a security notice acknowledging a 'newly observed issue'; watchTowr Labs reproduces the vulnerability.
- Cloud Software Group publishes CTX697174 for CVE-2026-88779 (SAML memory overflow DoS, CVSS v4.0 8.7) with fixed builds 14.1-73.41 and 13.1-64.28; credits Bishop Fox and watchTowr
- Researchers report crafted authentication usernames with shell commands that download a payload from 213.209.159.55 (saved as /v and executed), plus a honeypot running a downloaded binary; BleepingComputer describes it as 'sprayed and prayed' mass exploitation.
- CISA adds CVE-2026-88779 to the KEV Catalog; SecurityOnline reports active exploitation causing repeated appliance reboots on SAML-configured gateways
- HKCERT publishes a High-risk bulletin on the Citrix NetScaler denial-of-service vulnerability, reporting exploitation in the wild.
- KEV remediation due date per secondary source hol.org (not stated in CISA's alert)
Update history for TL-2026-2896
- 2026-10-05 — Citrix NetScaler ADC and Gateway SAML Memory Overflow Denial of Service (CVE-2026-88779) Exploited in the Wild: What changed No severity, exploitability or status change (already HIGH / ACTIVE). Added Citrix/CISA-confirmed exploitation context: Citrix reports targeted attacks on unmitigated deployments, CISA flags forensic triage, and the patch-bypas
- 2026-10-04 — Citrix NetScaler ADC/Gateway SAML buffer overflow zero-day (CVE-2026-88779) exploited in attacks: What changed No field escalation (already HIGH / ACTIVE). Exploitation detail added: crafted SAML auth requests crash nsaaad, Pitboss reboots the appliance after the restart limit; shell-command-in-username attempts fetching a payload sugge
Sources cited for CISA adds Citrix NetScaler SAML memory overflow DoS
- CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Known Exploited Vulnerabilities Catalog
- CVE-2026-88779 Record
- CISA BOD 26-04 Implementation Guidance
- Citrix NetScaler ADC and Gateway Security Bulletin for CVE-2026-88779 (CTX697174)
- Citrix NetScaler ADC and Gateway Security Bulletin for CVE-2026-88771 to CVE-2026-88778 (CTX697096)
- Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline
- BREAKING: NetScaler SAML memory overflow hits CISA KEV
- Warning: Two Unpatched Citrix NetScaler Flaws (CVE-2026-88771/88772)
- Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (Rescana)
- CSSF: Multiple critical vulnerabilities in Citrix NetScaler ADC and Gateway
- CIRCL Technical Report TR-100 on Citrix NetScaler exploitation
Detection coverage for TL-2026-2896
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2896 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.