Threat reportVulnerabilityTL-2026-2944

Citrix NetScaler ADC/Gateway SAML memory-overflow DoS CVE-2026-88779 actively exploited; added to CISA KEV alongside still-exploited CVE-2026-88771/88772

highACTIVE

Citrix NetScaler ADC/Gateway SAML memory-overflow DoS (TL-2026-2944) is a high-severity software vulnerability scored CVSS 8.7, first published 2026-10-05. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC, references 3 CVEs (CVE-2026-88779, CVE-2026-88771, CVE-2026-88772), maps to 9 MITRE ATT&CK techniques (T1021.002, T1027, T1059.004), and is covered by 9 detection rules and 11 indicators of compromise.

CVSS
8.7/10High
CVEs
3Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-2944

Threat ID
TL-2026-2944
Severity
HIGH
CVSS
8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, technology, education, telecoms, legal
Target regions
North America, Europe, australia
Detection rules
9
Indicators of compromise
11

How Citrix NetScaler ADC/Gateway SAML memory-overflow DoS works

CVE-2026-88779 (CVSS 4.0 8.7) is a memory-overflow flaw in NetScaler ADC and Gateway appliances configured as a SAML SP or IdP that lets an unauthenticated remote attacker crash the appliance. CISA added it to KEV on 2026-10-04 with a 2026-10-07 federal deadline, while the earlier critical RCE flaws CVE-2026-88771 and CVE-2026-88772 remain under wide exploitation.

CVE-2026-88779 is a memory overflow (CWE-119) in the SAML authentication handling of on-premises Citrix NetScaler ADC and NetScaler Gateway. Only appliances configured as a SAML Service Provider (add authentication samlAction) or SAML Identity Provider (add authentication samlIdPProfile) are vulnerable. Citrix advisory CTX697174 rates it CVSS v4.0 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N/VA:H) and states the confirmed impact is denial of service, with repeated exploitation leaving services unavailable and no confirmed data-integrity impact. Fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (FIPS/NDcPP). Cloud-hosted Citrix-managed services are not affected. The flaw was reported by Bishop Fox and watchTowr.

Exploitation was targeted at unmitigated deployments before the advisory. watchTowr reproduced the bug and found it can only crash systems; its founder suspects attackers crash appliances deliberately to speed exploitation of the earlier command-injection flaw CVE-2026-88771. Separately, researchers (via BleepingComputer, citing Kevin Beaumont) observed crafted SAML authentication usernames containing shell commands that download a payload from 213.209.159.55, save it as /v and execute it, and one honeypot reportedly ran a downloaded binary despite patching. That suggests possible code execution beyond the vendor-stated DoS impact; it is not confirmed by Citrix and technical details have not been published.

Context: Citrix's 2026-09-27 bulletin CTX697096 fixed eight flaws (CVE-2026-88771 to CVE-2026-88778). CVE-2026-88771 (CVSS 9.5, CWE-20) allows unauthenticated command execution in the default configuration; CVE-2026-88772 (CVSS 9.5, CWE-119) is a memory overflow leading to RCE or DoS when DTLS is enabled (default on VPN vservers). Both are in CISA KEV (added 2026-09-27) and have been exploited globally, with unique web shells per victim, anti-forensic log cleanup, and lateral movement to internal networks. Mandiant/GTIG traces CVE-2026-88772 exploitation to early September by suspected state-linked actors; no public attribution exists for the CVE-2026-88779 attacks. NetScaler 12.1 and 13.0 are end-of-life and unfixed.

Defenders should patch, preserve forensic evidence (logs, snapshots, support bundles, core dumps) before upgrading because an update can remove evidence, run the NetScaler Console IOC scan, review SAML configuration, monitor for unexpected crashes/reboots, and reset credentials and invalidate sessions if compromise is suspected.

MITRE ATT&CK techniques used in TL-2026-2944

Lateral Movement

T1021.002 SMB/Windows Admin Shares

Defense Evasion

T1027 Obfuscated Files or Information; T1070.004 File Deletion

Execution

T1059.004 Unix Shell

Discovery

T1087.002 Domain Account

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Application or System Exploitation

Persistence

T1505.003 Web Shell

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in Citrix NetScaler ADC/Gateway SAML memory-overflow DoS

  • Citrix (Cloud Software Group) — NetScaler ADC
    Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; 14.1 FIPS before 14.1-73.41 FIPS; 13.1 FIPS/NDcPP before 13.1-37.282
    Fixed in: 14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282
  • Citrix (Cloud Software Group) — NetScaler Gateway
    Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28
    Fixed in: 14.1-73.41; 13.1-64.28

Remediation for Citrix NetScaler ADC/Gateway SAML memory-overflow DoS

Patches

  • Citrix CTX697174 (CVE-2026-88779): 14.1-73.41+, 13.1-64.28+, 14.1-73.41 FIPS+, 13.1-37.282+
  • Citrix CTX697096 (CVE-2026-88771 to 88778): 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+, 13.1-37.279+

Immediate actions

  • Upgrade NetScaler ADC/Gateway to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS/NDcPP)
  • Identify appliances configured as SAML SP or IdP (add authentication samlAction / samlIdPProfile) and prioritize internet-facing ones
  • Preserve logs, snapshots, support bundles and core dumps BEFORE patching, since an update can remove evidence
  • Run the NetScaler Console IOC scan (14.1-73.36+ with telemetry enabled); a clean result is not proof of non-compromise
  • Hunt for crafted SAML usernames containing shell commands, a /v file on the appliance, and egress to 213.209.159.55

Workarounds

  • Where operationally feasible, temporarily take internet-facing vulnerable appliances offline (CCCS guidance)
  • Reset credentials and invalidate sessions if compromise is suspected
  • Apply Global Deny List signatures where available

Longer-term hardening

  • Remediate CVE-2026-88771 and CVE-2026-88772 from CTX697096 and assume prior compromise on unpatched exposed appliances
  • Enable file integrity monitoring on NetScaler and forward appliance logs off-box so local log deletion does not erase evidence
  • Reduce internet exposure of management and gateway interfaces; migrate off end-of-life 12.1 and 13.0 builds

CVEs associated with Citrix NetScaler ADC/Gateway SAML memory-overflow DoS

CVE-2026-88779, CVE-2026-88771, CVE-2026-88772

Weaknesses (CWE) in Citrix NetScaler ADC/Gateway SAML memory-overflow DoS

CWE-119, CWE-20

Timeline of Citrix NetScaler ADC/Gateway SAML memory-overflow DoS

  • Earliest observed exploitation of the NetScaler zero-days from 149.104.78.141; GreyNoise also detected attempts against NetScaler Gateway. Mandiant/GTIG traced CVE-2026-88772 exploitation to early September.
  • watchTowr publicly warned of in-the-wild exploitation of NetScaler ADC/Gateway.
  • Citrix published CTX697096 fixing eight flaws (CVE-2026-88771 to 88778); CISA added CVE-2026-88771 and CVE-2026-88772 to KEV.
  • watchTowr released a proof-of-concept for CVE-2026-88771; mass exploitation followed, with fewer than 10% of roughly 42,000 exposed NetScaler hosts patched.
  • Arctic Wolf and Mandiant published additional indicators of compromise for the NetScaler intrusions.
  • Canadian Centre for Cyber Security updated AL26-024: a separate SAML authentication issue affecting stability and enabling DoS had been identified.
  • Citrix published CTX697174 for CVE-2026-88779 (reported by Bishop Fox and watchTowr) after targeted attacks began; CISA added it to KEV.
  • US and Australian authorities publicly warned about CVE-2026-88779; researchers reported crafted SAML usernames pulling a payload from 213.209.159.55, and watchTowr suspected crashes are used to speed CVE-2026-88771 exploitation.
  • CISA remediation deadline for federal civilian agencies to patch CVE-2026-88779, with forensic triage required.

Sources cited for Citrix NetScaler ADC/Gateway SAML memory-overflow DoS

Detection coverage for TL-2026-2944

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2944 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2944

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats