# CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog

> CISA added CVE-2026-88779, a memory-buffer overflow (CWE-119) in Citrix NetScaler ADC and Gateway SAML authentication, to the Known Exploited Vulnerabilities Catalog on 2026-10-04. An unauthenticated remote attacker can repeatedly trigger the flaw to crash and reboot appliances configured as a SAML SP or IdP, causing sustained denial of service; exploitation in the wild is reported.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-05T02:36:36.751Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2896
- **ID:** TL-2026-2896
- **Severity:** HIGH (CVSS 8.7)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-88779

## Description

CVE-2026-88779 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway. Cloud Software Group's bulletin CTX697174 rates it CVSS v4.0 8.7 (High), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N, i.e. network-reachable, no authentication, no user interaction, impact limited to availability. The appliance is only vulnerable when configured as a SAML Service Provider or SAML Identity Provider; Citrix tells customers to look for 'add authentication samlAction' or 'add authentication samlIdPProfile' in the running configuration. Credit is given to Bishop Fox and watchTowr.

Exploitation: secondary reporting (SecurityOnline, 2026-10-04) states attackers trigger the overflow repeatedly, causing appliance reboots and persistent denial of service on SAML-configured gateways; the same source suggests interim measures of applying Global Deny List signatures via NetScaler Console and firewalling attacking IP addresses. No threat actor is attributed and no network IOCs (IPs, domains, hashes) have been published. CISA's alert gives no CVSS, CWE or explicit due date; a secondary source (hol.org) reports a KEV due date of 2026-10-07 and catalog version 2026.10.04. CISA characterizes this class of flaw as a frequent attack vector for malicious cyber actors posing significant risk to the federal enterprise, and BOD 26-04 requires rapid remediation of KEV entries on publicly exposed assets.

Context: CVE-2026-88779 is a separate bulletin from the CVE-2026-88771 through CVE-2026-88778 batch (CTX697096), which was disclosed about 2026-09-27. Of that batch, CVE-2026-88771 (unauthenticated RCE via improper input validation, CVSS 9.5) and CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 9.5) are confirmed exploited in the wild; secondary reporting says post-compromise activity there included webshells, credential theft and lateral movement. Those behaviors are NOT evidenced for CVE-2026-88779 itself, whose reported impact is DoS only. Defenders running NetScaler should treat both bulletins together because they affect the same product lines and branches.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1499.004 Application or System Exploitation
- T1505.003 Web Shell
- T1059 Command and Scripting Interpreter
- T1595.002 Vulnerability Scanning
- T1059.004 Command and Scripting Interpreter
- T1105 Ingress Tool Transfer
- T1499 Endpoint Denial of Service

## Sources

- [CISA Adds One Known Exploited Vulnerability to Catalog](https://www.cisa.gov/news-events/alerts/2026/10/04/cisa-adds-one-known-exploited-vulnerability-catalog)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [CVE-2026-88779 Record](https://www.cve.org/CVERecord?id=CVE-2026-88779)
- [CISA BOD 26-04 Implementation Guidance](https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk)
- [Citrix NetScaler ADC and Gateway Security Bulletin for CVE-2026-88779 (CTX697174)](https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html)
- [Citrix NetScaler ADC and Gateway Security Bulletin for CVE-2026-88771 to CVE-2026-88778 (CTX697096)](https://support.citrix.com/external/article/CTX697096)
- [Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline](https://securityonline.info/citrix-netscaler-cve-2026-88779-exploited/)
- [BREAKING: NetScaler SAML memory overflow hits CISA KEV](https://hol.org/blog/cve-2026-88779-netscaler-saml-memory-overflow-dos-kev)
- [Warning: Two Unpatched Citrix NetScaler Flaws (CVE-2026-88771/88772)](https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html)
- [Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (Rescana)](https://rescana.com/post/active-exploitation-of-citrix-netscaler-adc-and-gateway-zero-day-vulnerabilities-cve-2026-88771-cve-2026-88772-urgent-pa)
- [CSSF: Multiple critical vulnerabilities in Citrix NetScaler ADC and Gateway](https://www.cssf.lu/fr/2026/09/multiples-vulnerabilites-critiques-dans-citrix-netscaler-adc-et-netscaler-gateway/)
- [CIRCL Technical Report TR-100 on Citrix NetScaler exploitation](https://www.circl.lu/pub/tr-100/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2896
