high severityConfidence highHistorical record

NetScaler SAML memory overflow hits CISA KEV

CISA added CVE-2026-88779 to KEV on 2026-10-04 (due 2026-10-07, forensic triage Yes, catalogVersion 2026.10.04). Citrix NetScaler ADC/Gateway memory-buffer overflow (CWE-119) on appliances configured as SAML SP (samlAction) or SAML IdP (samlIdPProfile): unauthenticated network path can cause denial of service. Vendor CVSS v4.0 base 8.7 High (availability High only). Fixed builds: 14.1-73.41+, 13.1-64.28+, FIPS 14.1-73.41 FIPS / 13.1-37.282+. Customer-managed appliances only; Citrix-managed cloud patched by CSG. Distinct from September CVE-2026-88771 RCE cluster.

Also tracked as CVE-2026-88779 · CTX697174 · Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

First observed
Oct 4, 2026
Last observed
Oct 4, 2026
Last reviewed
Oct 4, 2026
Tracking ended
Oct 4, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

Guard evidence pack still showed exploitation not marked at publish time while CISA KEV lists known exploitation. Exact crash request shape not fully public. Known ransomware campaign use Unknown.

  • Not in scope without SAML SP (samlAction) or SAML IdP (samlIdPProfile) configured.
  • Citrix-managed cloud / Adaptive Authentication patched by Cloud Software Group, not this customer-managed bulletin.
  • Not the September CVE-2026-88771 unauthenticated RCE cluster; confirm separate fix trains.
  • Impact is denial of service, not remote code execution.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • not covered

    NetScaler is an edge ADC/Gateway appliance outside Guard Desktop/Inbox agent runtime interception. Campaign tracks the CVE for AEO/SEO; Guard does not claim to block NetScaler SAML crashes.

No campaign-specific policy guidance is published.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. Disclosure

    Citrix published CTX697174 for CVE-2026-88779 (PST initial publication).

  2. Disclosure

    CVE-2026-88779 published to CVE/NVD feeds.

  3. Vendor action

    CISA added CVE-2026-88779 to KEV catalog 2026.10.04; dueDate 2026-10-07; forensic triage Yes.

  4. Update

    HOL Guard published operator write-up on hol.org/blog.

Publication clock: 43.4 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • NetScaler ADC@14.1 before 14.1-73.41; 13.1 before 13.1-64.28; FIPS before matching fixed buildscitrixpackage
  • NetScaler Gateway@14.1 before 14.1-73.41; 13.1 before 13.1-64.28citrixpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Security Publishing.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-8A1B9783