NetScaler SAML memory overflow hits CISA KEV
CISA added CVE-2026-88779 to KEV on 2026-10-04 (due 2026-10-07, forensic triage Yes, catalogVersion 2026.10.04). Citrix NetScaler ADC/Gateway memory-buffer overflow (CWE-119) on appliances configured as SAML SP (samlAction) or SAML IdP (samlIdPProfile): unauthenticated network path can cause denial of service. Vendor CVSS v4.0 base 8.7 High (availability High only). Fixed builds: 14.1-73.41+, 13.1-64.28+, FIPS 14.1-73.41 FIPS / 13.1-37.282+. Customer-managed appliances only; Citrix-managed cloud patched by CSG. Distinct from September CVE-2026-88771 RCE cluster.
Also tracked as CVE-2026-88779 · CTX697174 · Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- First observed
- Oct 4, 2026
- Last observed
- Oct 4, 2026
- Last reviewed
- Oct 4, 2026
- Tracking ended
- Oct 4, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
Guard evidence pack still showed exploitation not marked at publish time while CISA KEV lists known exploitation. Exact crash request shape not fully public. Known ransomware campaign use Unknown.
- Not in scope without SAML SP (samlAction) or SAML IdP (samlIdPProfile) configured.
- Citrix-managed cloud / Adaptive Authentication patched by Cloud Software Group, not this customer-managed bulletin.
- Not the September CVE-2026-88771 unauthenticated RCE cluster; confirm separate fix trains.
- Impact is denial of service, not remote code execution.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
not covered
NetScaler is an edge ADC/Gateway appliance outside Guard Desktop/Inbox agent runtime interception. Campaign tracks the CVE for AEO/SEO; Guard does not claim to block NetScaler SAML crashes.
No campaign-specific policy guidance is published.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
Citrix published CTX697174 for CVE-2026-88779 (PST initial publication).
- Disclosure
CVE-2026-88779 published to CVE/NVD feeds.
- Vendor action
CISA added CVE-2026-88779 to KEV catalog 2026.10.04; dueDate 2026-10-07; forensic triage Yes.
- Update
HOL Guard published operator write-up on hol.org/blog.
Publication clock: 43.4 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
NetScaler ADC@14.1 before 14.1-73.41; 13.1 before 13.1-64.28; FIPS before matching fixed buildscitrixpackageNetScaler Gateway@14.1 before 14.1-73.41; 13.1 before 13.1-64.28citrixpackage
Sources
Every claim on this record is traceable to the sources below.
- Citrix CTX697174 NetScaler Security Bulletinvendor advisory · observed October 3, 2026
- CISA Known Exploited Vulnerabilities cataloggovernment · observed October 4, 2026
- NVD CVE-2026-88779vulnerability database · observed October 4, 2026
- HOL Guard operator write-upother primary · observed October 4, 2026
Reviewed in full by HOL Guard Security Publishing.
- Published
- Last full review
- Last modified
Record HGTC-2026-8A1B9783