{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-8A1B9783",
  "slug": "cve-2026-88779-netscaler-saml-memory-overflow-dos-kev",
  "title": "NetScaler SAML memory overflow hits CISA KEV",
  "aliases": [
    "CVE-2026-88779",
    "CTX697174",
    "Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"
  ],
  "summary": "CISA added CVE-2026-88779 to KEV on 2026-10-04 (due 2026-10-07, forensic triage Yes, catalogVersion 2026.10.04). Citrix NetScaler ADC/Gateway memory-buffer overflow (CWE-119) on appliances configured as SAML SP (samlAction) or SAML IdP (samlIdPProfile): unauthenticated network path can cause denial of service. Vendor CVSS v4.0 base 8.7 High (availability High only). Fixed builds: 14.1-73.41+, 13.1-64.28+, FIPS 14.1-73.41 FIPS / 13.1-37.282+. Customer-managed appliances only; Citrix-managed cloud patched by CSG. Distinct from September CVE-2026-88771 RCE cluster.",
  "status": "published",
  "severity": "high",
  "confidence": "high",
  "uncertainty": "Guard evidence pack still showed exploitation not marked at publish time while CISA KEV lists known exploitation. Exact crash request shape not fully public. Known ransomware campaign use Unknown.",
  "firstObservedAt": "2026-10-04T04:16:43.680Z",
  "lastObservedAt": "2026-10-04T19:15:26.880Z",
  "publishedAt": "2026-10-04T19:23:20.896Z",
  "reviewedAt": "2026-10-04T19:23:11.867Z",
  "expiresAt": "2026-10-04T19:15:26.880Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "ctx697174",
      "label": "Citrix CTX697174 NetScaler Security Bulletin",
      "url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-10-03T00:00:00.000Z"
    },
    {
      "id": "cisa-kev",
      "label": "CISA Known Exploited Vulnerabilities catalog",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88779",
      "sourceType": "government",
      "observedAt": "2026-10-04T00:00:00.000Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-88779",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88779",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-10-04T04:16:43.680Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-88779-netscaler-saml-memory-overflow-dos-kev",
      "sourceType": "other_primary",
      "observedAt": "2026-10-04T19:15:26.880Z"
    }
  ],
  "artifacts": [
    {
      "id": "netscaler-adc",
      "artifactClass": "package",
      "ecosystem": "citrix",
      "name": "NetScaler ADC",
      "version": "14.1 before 14.1-73.41; 13.1 before 13.1-64.28; FIPS before matching fixed builds",
      "defanged": false
    },
    {
      "id": "netscaler-gateway",
      "artifactClass": "package",
      "ecosystem": "citrix",
      "name": "NetScaler Gateway",
      "version": "14.1 before 14.1-73.41; 13.1 before 13.1-64.28",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "vendor-bulletin",
      "occurredAt": "2026-10-03T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "Citrix published CTX697174 for CVE-2026-88779 (PST initial publication).",
      "sourceIds": [
        "ctx697174"
      ]
    },
    {
      "id": "cve-published",
      "occurredAt": "2026-10-04T04:16:43.680Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-88779 published to CVE/NVD feeds.",
      "sourceIds": [
        "nvd"
      ]
    },
    {
      "id": "kev-added",
      "occurredAt": "2026-10-04T18:52:56.063Z",
      "eventType": "vendor_action",
      "summary": "CISA added CVE-2026-88779 to KEV catalog 2026.10.04; dueDate 2026-10-07; forensic triage Yes.",
      "sourceIds": [
        "cisa-kev"
      ]
    },
    {
      "id": "hol-blog",
      "occurredAt": "2026-10-04T19:15:26.880Z",
      "eventType": "other",
      "summary": "HOL Guard published operator write-up on hol.org/blog.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [
    {
      "assertionId": "edge-appliance-not-agent-runtime",
      "relationship": "not_covered",
      "limitation": "NetScaler is an edge ADC/Gateway appliance outside Guard Desktop/Inbox agent runtime interception. Campaign tracks the CVE for AEO/SEO; Guard does not claim to block NetScaler SAML crashes."
    }
  ],
  "policies": [],
  "limitations": [
    "Not in scope without SAML SP (samlAction) or SAML IdP (samlIdPProfile) configured.",
    "Citrix-managed cloud / Adaptive Authentication patched by Cloud Software Group, not this customer-managed bulletin.",
    "Not the September CVE-2026-88771 unauthenticated RCE cluster; confirm separate fix trains.",
    "Impact is denial of service, not remote code execution."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-88779-netscaler-saml-memory-overflow-dos-kev/corrections"
}
