Threat reportVulnerabilityTL-2026-2944
Citrix NetScaler ADC/Gateway SAML memory-overflow DoS CVE-2026-88779 actively exploited; added to CISA KEV alongside still-exploited CVE-2026-88771/88772
Citrix NetScaler ADC/Gateway SAML memory-overflow DoS (TL-2026-2944) is a high-severity software vulnerability scored CVSS 8.7, first published 2026-10-05. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC, references 3 CVEs (CVE-2026-88779, CVE-2026-88771, CVE-2026-88772), maps to 9 MITRE ATT&CK techniques (T1021.002, T1027, T1059.004), and is covered by 9 detection rules and 11 indicators of compromise.
- CVSS
- 8.7/10High
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-2944
- Threat ID
- TL-2026-2944
- Severity
- HIGH
- CVSS
- 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, technology, education, telecoms, legal
- Target regions
- North America, Europe, australia
- Detection rules
- 9
- Indicators of compromise
- 11
How Citrix NetScaler ADC/Gateway SAML memory-overflow DoS works
CVE-2026-88779 (CVSS 4.0 8.7) is a memory-overflow flaw in NetScaler ADC and Gateway appliances configured as a SAML SP or IdP that lets an unauthenticated remote attacker crash the appliance. CISA added it to KEV on 2026-10-04 with a 2026-10-07 federal deadline, while the earlier critical RCE flaws CVE-2026-88771 and CVE-2026-88772 remain under wide exploitation.
CVE-2026-88779 is a memory overflow (CWE-119) in the SAML authentication handling of on-premises Citrix NetScaler ADC and NetScaler Gateway. Only appliances configured as a SAML Service Provider (add authentication samlAction) or SAML Identity Provider (add authentication samlIdPProfile) are vulnerable. Citrix advisory CTX697174 rates it CVSS v4.0 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N/VA:H) and states the confirmed impact is denial of service, with repeated exploitation leaving services unavailable and no confirmed data-integrity impact. Fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (FIPS/NDcPP). Cloud-hosted Citrix-managed services are not affected. The flaw was reported by Bishop Fox and watchTowr.
Exploitation was targeted at unmitigated deployments before the advisory. watchTowr reproduced the bug and found it can only crash systems; its founder suspects attackers crash appliances deliberately to speed exploitation of the earlier command-injection flaw CVE-2026-88771. Separately, researchers (via BleepingComputer, citing Kevin Beaumont) observed crafted SAML authentication usernames containing shell commands that download a payload from 213.209.159.55, save it as /v and execute it, and one honeypot reportedly ran a downloaded binary despite patching. That suggests possible code execution beyond the vendor-stated DoS impact; it is not confirmed by Citrix and technical details have not been published.
Context: Citrix's 2026-09-27 bulletin CTX697096 fixed eight flaws (CVE-2026-88771 to CVE-2026-88778). CVE-2026-88771 (CVSS 9.5, CWE-20) allows unauthenticated command execution in the default configuration; CVE-2026-88772 (CVSS 9.5, CWE-119) is a memory overflow leading to RCE or DoS when DTLS is enabled (default on VPN vservers). Both are in CISA KEV (added 2026-09-27) and have been exploited globally, with unique web shells per victim, anti-forensic log cleanup, and lateral movement to internal networks. Mandiant/GTIG traces CVE-2026-88772 exploitation to early September by suspected state-linked actors; no public attribution exists for the CVE-2026-88779 attacks. NetScaler 12.1 and 13.0 are end-of-life and unfixed.
Defenders should patch, preserve forensic evidence (logs, snapshots, support bundles, core dumps) before upgrading because an update can remove evidence, run the NetScaler Console IOC scan, review SAML configuration, monitor for unexpected crashes/reboots, and reset credentials and invalidate sessions if compromise is suspected.
MITRE ATT&CK techniques used in TL-2026-2944
Lateral Movement
T1021.002 SMB/Windows Admin Shares
Defense Evasion
T1027 Obfuscated Files or Information; T1070.004 File Deletion
Execution
Discovery
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Persistence
defense-impairment
Affected products and versions in Citrix NetScaler ADC/Gateway SAML memory-overflow DoS
- Citrix (Cloud Software Group) — NetScaler ADC
Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28; 14.1 FIPS before 14.1-73.41 FIPS; 13.1 FIPS/NDcPP before 13.1-37.282
Fixed in: 14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282 - Citrix (Cloud Software Group) — NetScaler Gateway
Vulnerable versions: 14.1 before 14.1-73.41; 13.1 before 13.1-64.28
Fixed in: 14.1-73.41; 13.1-64.28
Remediation for Citrix NetScaler ADC/Gateway SAML memory-overflow DoS
Patches
- Citrix CTX697174 (CVE-2026-88779): 14.1-73.41+, 13.1-64.28+, 14.1-73.41 FIPS+, 13.1-37.282+
- Citrix CTX697096 (CVE-2026-88771 to 88778): 14.1-73.37+, 13.1-64.23+, 14.1-73.37 FIPS+, 13.1-37.279+
Immediate actions
- Upgrade NetScaler ADC/Gateway to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS/NDcPP)
- Identify appliances configured as SAML SP or IdP (add authentication samlAction / samlIdPProfile) and prioritize internet-facing ones
- Preserve logs, snapshots, support bundles and core dumps BEFORE patching, since an update can remove evidence
- Run the NetScaler Console IOC scan (14.1-73.36+ with telemetry enabled); a clean result is not proof of non-compromise
- Hunt for crafted SAML usernames containing shell commands, a /v file on the appliance, and egress to 213.209.159.55
Workarounds
- Where operationally feasible, temporarily take internet-facing vulnerable appliances offline (CCCS guidance)
- Reset credentials and invalidate sessions if compromise is suspected
- Apply Global Deny List signatures where available
Longer-term hardening
- Remediate CVE-2026-88771 and CVE-2026-88772 from CTX697096 and assume prior compromise on unpatched exposed appliances
- Enable file integrity monitoring on NetScaler and forward appliance logs off-box so local log deletion does not erase evidence
- Reduce internet exposure of management and gateway interfaces; migrate off end-of-life 12.1 and 13.0 builds
CVEs associated with Citrix NetScaler ADC/Gateway SAML memory-overflow DoS
Weaknesses (CWE) in Citrix NetScaler ADC/Gateway SAML memory-overflow DoS
Timeline of Citrix NetScaler ADC/Gateway SAML memory-overflow DoS
- Earliest observed exploitation of the NetScaler zero-days from 149.104.78.141; GreyNoise also detected attempts against NetScaler Gateway. Mandiant/GTIG traced CVE-2026-88772 exploitation to early September.
- watchTowr publicly warned of in-the-wild exploitation of NetScaler ADC/Gateway.
- Citrix published CTX697096 fixing eight flaws (CVE-2026-88771 to 88778); CISA added CVE-2026-88771 and CVE-2026-88772 to KEV.
- watchTowr released a proof-of-concept for CVE-2026-88771; mass exploitation followed, with fewer than 10% of roughly 42,000 exposed NetScaler hosts patched.
- Arctic Wolf and Mandiant published additional indicators of compromise for the NetScaler intrusions.
- Canadian Centre for Cyber Security updated AL26-024: a separate SAML authentication issue affecting stability and enabling DoS had been identified.
- Citrix published CTX697174 for CVE-2026-88779 (reported by Bishop Fox and watchTowr) after targeted attacks began; CISA added it to KEV.
- US and Australian authorities publicly warned about CVE-2026-88779; researchers reported crafted SAML usernames pulling a payload from 213.209.159.55, and watchTowr suspected crashes are used to speed CVE-2026-88771 exploitation.
- CISA remediation deadline for federal civilian agencies to patch CVE-2026-88779, with forensic triage required.
Sources cited for Citrix NetScaler ADC/Gateway SAML memory-overflow DoS
- US, Australia warn of latest Citrix vulnerability (The Record)
- Citrix Security Bulletin CTX697174 (CVE-2026-88779)
- Citrix Security Bulletin CTX697096 (CVE-2026-88771 to CVE-2026-88778)
- Citrix patches NetScaler SAML zero-day exploited in attacks (BleepingComputer)
- CVE-2026-88779: Citrix NetScaler Zero-Day Exploited Against SAML Deployments (SOC Prime)
- CISA flags new exploited NetScaler flaw as attackers crash appliances (Help Net Security)
- Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772 (watchTowr)
- Citrix NetScaler Zero-Day: Detecting and Investigating CVE-2026-88771 and CVE-2026-88772 (Prophet Security)
- Citrix NetScaler Zero-Day: CVE-2026-88771 and CVE-2026-88772 in Active Exploitation (Sophos)
- Canadian Centre for Cyber Security AL26-024: Critical vulnerabilities affecting Citrix NetScaler ADC and Gateway
- NCSC UK: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway
- U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog (Security Affairs)
- NetScaler zero-day exploitation escalates into mass attacks (Help Net Security)
- Citrix NetScaler exploitation began days before customer notification (Cybersecurity Dive)
Detection coverage for TL-2026-2944
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2944 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2944
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.