{"type":"bundle","id":"bundle--1d57be70-6274-5bd1-81fb-0719e7c5d525","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--51d1cd79-dacc-5958-ab3d-a6aa144f8c37","created":"2026-10-04T19:23:20.896Z","modified":"2026-10-04T19:23:20.896Z","name":"NetScaler SAML memory overflow hits CISA KEV","description":"CISA added CVE-2026-88779 to KEV on 2026-10-04 (due 2026-10-07, forensic triage Yes, catalogVersion 2026.10.04). Citrix NetScaler ADC/Gateway memory-buffer overflow (CWE-119) on appliances configured as SAML SP (samlAction) or SAML IdP (samlIdPProfile): unauthenticated network path can cause denial of service. Vendor CVSS v4.0 base 8.7 High (availability High only). Fixed builds: 14.1-73.41+, 13.1-64.28+, FIPS 14.1-73.41 FIPS / 13.1-37.282+. Customer-managed appliances only; Citrix-managed cloud patched by CSG. Distinct from September CVE-2026-88771 RCE cluster.","aliases":["CVE-2026-88779","CTX697174","Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability"],"first_seen":"2026-10-04T04:16:43.680Z","last_seen":"2026-10-04T19:15:26.880Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Citrix CTX697174 NetScaler Security Bulletin","url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174"},{"source_name":"CISA Known Exploited Vulnerabilities catalog","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88779"},{"source_name":"NVD CVE-2026-88779","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88779"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-88779-netscaler-saml-memory-overflow-dos-kev"}]}]}