Cyber Threat Brief — October 5 2026

⚠️ This report is AI-generated. Always validate findings.

1. NetScaler SAML memory overflow now on KEV — CVE-2026-88779

TL;DR: CISA added CVE-2026-88779 to KEV on 2026-10-04 (catalog 2026.10.04, count 1734), with due date 2026-10-07 and forensic triage Yes. Find every customer-managed NetScaler with SAML SP or IdP config and move it to the fixed builds before you treat the Global Deny List as enough.

What’s New:

  • Yesterday’s brief recorded CTX697174 as a DoS bulletin that was not in KEV. Overnight that changed: CISA’s catalog short description is still denial of service, and the federal due date is 2026-10-07.
  • Citrix (CTX697174 and the NetScaler CTI post) still rates CVSS v4.0 8.7 with impact on availability only. Fixed builds are 14.1-73.41, 13.1-64.28, FIPS 14.1-73.41, and NDcPP 13.1-37.282. September’s CTX697096 builds do not close this CVE.
  • Beazley Security’s 2026-10-04 update says the crash is tied to an oversized InclusiveNamespaces PrefixList while nsaaad processes SAML canonicalization, and that actors have used the reboot to re-fire CVE-2026-88771 log injection on appliances that were not patched for that earlier pair. On boxes already fixed for 88771, Beazley reports no code execution from this DoS alone.
  • Community and researcher notes (Beaumont honeypot malware; Reddit username strings pointing at 213.209.159.55//t///v) preceded the KEV add. Citrix has not attributed those payload indicators to CVE-2026-88779. Keep them as campaign-adjacent hunts, not as vendor-proven RCE for this CVE.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
NetScaler ADC/Gateway builds before 14.1-73.41 / 13.1-64.28 (FIPS 14.1-73.41; FIPS/NDcPP 13.1-37.282) when SAML preconditions applyVulnerable appT1190show ns version / inventory / HA peer build listList every customer-managed ADC and Gateway, including Secure Private Access Hybrid instances. If the running build is below the fixed line for its branch and SAML is configured, upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS/NDcPP build. Preserve logs and crash dumps before the upgrade when you can.
Config lines add authentication samlAction or add authentication samlIdPProfileExposure preconditionT1190/flash/nsconfig/ns.conf / show ns runningConfigGrep saved and running config for add authentication samlAction and add authentication samlIdPProfile. A hit means the CVE precondition is met for that node. Record both HA peers.
Global Deny List signatures with Encrypted Version ≥24, Virtual patching enabled, only on 14.1-73.37–<14.1-73.41 or 13.1-64.23–<13.1-64.28Interim mitigationT1190NetScaler Console Virtual patching status / show appfw signatures / stat denylist global AAA_REQUESTIf you cannot upgrade today and the node is in the Citrix-documented build window, enable Virtual patching in Console, confirm default signatures Encrypted Version is 24 or higher, and check stat denylist global AAA_REQUEST counters. This is a bridge. The fix remains the fixed firmware.
Repeated nsaaad exits (community reports cite status 0x8a) followed by Pitboss restart exhaustion and appliance rebootCrash / DoS symptomT1499/var/log/ns.log, /var/log/messages, /var/coreAlert on clusters of nsaaad failures that end in Pitboss restart-limit reboot on SAML-enabled nodes. Copy /var/core and the matching ns.log window before rebuild. A crash alone is not proof of code execution.
Oversized SAML InclusiveNamespaces PrefixList processed by nsaaad (Beazley 2026-10-04 technical note)Exploit trigger shapeT1190SAML/IdP or AAA auth logs correlated with nsaaad exitsWhen investigating a crash window, retain the SAML request that arrived just before nsaaad died and look for an abnormal InclusiveNamespaces PrefixList. Treat that packet capture or log extract as evidence for IR, not as a public Nuclei check.
Outbound to 213.209.159.55 (paths under /t/) or local file /v / /tmp/v / /var/tmp/vCampaign-adjacent indicatorT1105Egress firewall / NetScaler outbound / filesystemSearch egress and appliance records for 213.209.159.55 and for unexpected /v under /, /tmp, or /var/tmp. Citrix has not tied these to CVE-2026-88779. A hit is a lead for the broader NetScaler campaign (including 88771 post-ex), not proof this CVE executed code.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedCitrix ADC Exploitation CVE-2023-3519 watches POST paths such as /cgi/samlauth and /saml/login. It does not look for InclusiveNamespaces abuse or nsaaad crash loops. CitrixBleed 2 rules target /p/u/doAuthentication.do.
ElasticNone — verifiedLocal elastic_dr tree has no rule whose logic matches NetScaler SAML PrefixList overflow or nsaaad/Pitboss restart exhaustion for this CVE.
SigmaNone — verifiedEmerging-threat Citrix rules cover CVE-2019-19781, CVE-2020-8193/8195, and CVE-2023-4966. None name CVE-2026-88779 or the SAML PrefixList trigger.

Hunt hint: On each internet-facing ADC or Gateway, record show ns version and whether samlAction or samlIdPProfile is present. Pull ns.log around any reboot since Thursday 2026-10-02. If you see nsaaad dying into a Pitboss restart loop on a SAML node that is still below 14.1-73.41 / 13.1-64.28, treat that host as KEV-scope: preserve evidence, upgrade, and run the existing 88771 webshell hunts (LogonPoint/custom, httpd.conf PHP/SetHandler, WHIPSHOT/SLAPSHOT paths) because Beazley ties the reboot to re-firing that older injection on unpatched boxes. Do not stop at Global Deny List.

Sources: CISA KEV alert 2026-10-04 · CTX697174 · Citrix CTI guidance · BleepingComputer · Beazley BSL-A1216 · SecurityWeek


Status Updates

  • CVE-2026-102489 (Zammad): KEV due TODAY 2026-10-05; forensic triage Yes. Session hijack to code as zammad on 6.3.0–6.5.4. Interim build 7.2.0. Oct 3 brief.
  • CVE-2026-102490 (Zammad): KEV due TODAY 2026-10-05; forensic triage Yes. Local zammad to root. No confirmed fixed build beyond moving off the affected line. Oct 3 brief.
  • CVE-2026-104286 (FortiMail): KEV due was 2026-10-04; forensic triage Yes. SecPod’s 2026-10-05 read of FG-IR-26-175 still lists fixed builds as upcoming (8.0.2, 7.6.7, 7.4.9; 7.2 moves to 7.4). Keep /data/etc/ld.so.preload and liblog.so hunts, and the IBE workaround. Oct 2 brief.
  • CVE-2026-61500 (Rejetto HFS): No material change. Still not CISA KEV. Keep 3.0.0–3.2.0 → ≥3.2.1, /~/api/loginSrp1, and server_code hunts. Oct 4 brief.
  • CVE-2026-88062 (OmniRoute): No material change. Version line still disputed. Keep POST /api/acp/agents and requireLogin=false hunts. Oct 4 brief.
  • CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due was 2026-10-03; forensic triage Yes. Confirm fixed builds and URI-encoded j_security_check hunts. Oct 1 brief.
  • CVE-2026-86950 (Apple CoreGraphics): KEV due was 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
  • CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. Beazley’s 88779 note re-ties reboots to this log-injection chain on unpatched boxes. Keep LevelBlue sec_monitor / .local_journal and Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief.
  • CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds. DTLS-off is temporary only for this CVE. Sep 28 brief.
  • GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep mcp ≥1.30.0 / ≥2.2.0 and issuer= on unattended providers. Sep 29 brief.
  • CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds and sphealth.aspx hunts. Sep 26 brief.
  • CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
  • CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
  • Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375, GH0ST/SOUL.md, and elementor/v1/events/ hunts. Elementor ≥4.3.2. Sep 28 brief.