# Citrix NetScaler ADC/Gateway SAML memory-overflow DoS CVE-2026-88779 actively exploited; added to CISA KEV alongside still-exploited CVE-2026-88771/88772

> CVE-2026-88779 (CVSS 4.0 8.7) is a memory-overflow flaw in NetScaler ADC and Gateway appliances configured as a SAML SP or IdP that lets an unauthenticated remote attacker crash the appliance. CISA added it to KEV on 2026-10-04 with a 2026-10-07 federal deadline, while the earlier critical RCE flaws CVE-2026-88771 and CVE-2026-88772 remain under wide exploitation.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2944
- **ID:** TL-2026-2944
- **Severity:** HIGH (CVSS 8.7)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-88779, CVE-2026-88771, CVE-2026-88772

## Description

CVE-2026-88779 is a memory overflow (CWE-119) in the SAML authentication handling of on-premises Citrix NetScaler ADC and NetScaler Gateway. Only appliances configured as a SAML Service Provider (add authentication samlAction) or SAML Identity Provider (add authentication samlIdPProfile) are vulnerable. Citrix advisory CTX697174 rates it CVSS v4.0 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N/VA:H) and states the confirmed impact is denial of service, with repeated exploitation leaving services unavailable and no confirmed data-integrity impact. Fixed builds are 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (FIPS/NDcPP). Cloud-hosted Citrix-managed services are not affected. The flaw was reported by Bishop Fox and watchTowr.

Exploitation was targeted at unmitigated deployments before the advisory. watchTowr reproduced the bug and found it can only crash systems; its founder suspects attackers crash appliances deliberately to speed exploitation of the earlier command-injection flaw CVE-2026-88771. Separately, researchers (via BleepingComputer, citing Kevin Beaumont) observed crafted SAML authentication usernames containing shell commands that download a payload from 213.209.159.55, save it as /v and execute it, and one honeypot reportedly ran a downloaded binary despite patching. That suggests possible code execution beyond the vendor-stated DoS impact; it is not confirmed by Citrix and technical details have not been published.

Context: Citrix's 2026-09-27 bulletin CTX697096 fixed eight flaws (CVE-2026-88771 to CVE-2026-88778). CVE-2026-88771 (CVSS 9.5, CWE-20) allows unauthenticated command execution in the default configuration; CVE-2026-88772 (CVSS 9.5, CWE-119) is a memory overflow leading to RCE or DoS when DTLS is enabled (default on VPN vservers). Both are in CISA KEV (added 2026-09-27) and have been exploited globally, with unique web shells per victim, anti-forensic log cleanup, and lateral movement to internal networks. Mandiant/GTIG traces CVE-2026-88772 exploitation to early September by suspected state-linked actors; no public attribution exists for the CVE-2026-88779 attacks. NetScaler 12.1 and 13.0 are end-of-life and unfixed.

Defenders should patch, preserve forensic evidence (logs, snapshots, support bundles, core dumps) before upgrading because an update can remove evidence, run the NetScaler Console IOC scan, review SAML configuration, monitor for unexpected crashes/reboots, and reset credentials and invalidate sessions if compromise is suspected.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1499.004 Application or System Exploitation
- T1059.004 Unix Shell
- T1505.003 Web Shell
- T1685.006 Clear Linux or Mac System Logs
- T1070.004 File Deletion
- T1027 Obfuscated Files or Information
- T1087.002 Domain Account
- T1021.002 SMB/Windows Admin Shares

## Sources

- [US, Australia warn of latest Citrix vulnerability (The Record)](https://therecord.media/us-australia-warn-of-latest-citrix-vulnerability)
- [Citrix Security Bulletin CTX697174 (CVE-2026-88779)](https://support.citrix.com/external/article/CTX697174)
- [Citrix Security Bulletin CTX697096 (CVE-2026-88771 to CVE-2026-88778)](https://support.citrix.com/external/article/CTX697096)
- [Citrix patches NetScaler SAML zero-day exploited in attacks (BleepingComputer)](https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/)
- [CVE-2026-88779: Citrix NetScaler Zero-Day Exploited Against SAML Deployments (SOC Prime)](https://socprime.com/blog/cve-2026-88779-citrix-netscaler-zero-day-exploited-against-saml-deployments/)
- [CISA flags new exploited NetScaler flaw as attackers crash appliances (Help Net Security)](https://www.hendryadrian.com/cisa-flags-new-exploited-netscaler-flaw-as-attackers-crash-appliances-cve-2026-88779-help-net-security/)
- [Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772 (watchTowr)](https://watchtowr.com/intelligence/citrix-netscaler-zero-day-vulnerabilities-faq/)
- [Citrix NetScaler Zero-Day: Detecting and Investigating CVE-2026-88771 and CVE-2026-88772 (Prophet Security)](https://www.prophetsecurity.ai/blog/citrix-netscaler-zero-day)
- [Citrix NetScaler Zero-Day: CVE-2026-88771 and CVE-2026-88772 in Active Exploitation (Sophos)](https://www.sophos.com/en-us/blog/citrix-netscaler-cve-2026-88771-cve-2026-88772-in-active-exploitation)
- [Canadian Centre for Cyber Security AL26-024: Critical vulnerabilities affecting Citrix NetScaler ADC and Gateway](https://cyber.gc.ca/en/alerts-advisories/al26-024-critical-vulnerabilities-affecting-citrix-netscaler-adc-netscaler-gateway-cve-2026-88771-cve-2026-88772)
- [NCSC UK: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway](https://www.ncsc.gov.uk/sites/default/files/2026-09/Exploitation-of-vulnerabilities-affecting-Citrix-NetScaler-ADC-and-Citrix-NetScaler-Gateway.pdf)
- [U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog (Security Affairs)](https://securityaffairs.com/?p=199891)
- [NetScaler zero-day exploitation escalates into mass attacks (Help Net Security)](https://www.helpnetsecurity.com/?p=386203)
- [Citrix NetScaler exploitation began days before customer notification (Cybersecurity Dive)](https://www.cybersecuritydive.com/news/citrix-netscaler-exploitation-days-before-notification/831634/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2944
