Cyber Threat Brief — October 5 2026
1. NetScaler SAML memory overflow now on KEV — CVE-2026-88779
TL;DR: CISA added CVE-2026-88779 to KEV on 2026-10-04 (catalog 2026.10.04, count 1734), with due date 2026-10-07 and forensic triage Yes. Find every customer-managed NetScaler with SAML SP or IdP config and move it to the fixed builds before you treat the Global Deny List as enough.
What’s New:
- Yesterday’s brief recorded CTX697174 as a DoS bulletin that was not in KEV. Overnight that changed: CISA’s catalog short description is still denial of service, and the federal due date is 2026-10-07.
- Citrix (CTX697174 and the NetScaler CTI post) still rates CVSS v4.0 8.7 with impact on availability only. Fixed builds are 14.1-73.41, 13.1-64.28, FIPS 14.1-73.41, and NDcPP 13.1-37.282. September’s CTX697096 builds do not close this CVE.
- Beazley Security’s 2026-10-04 update says the crash is tied to an oversized InclusiveNamespaces PrefixList while
nsaaadprocesses SAML canonicalization, and that actors have used the reboot to re-fire CVE-2026-88771 log injection on appliances that were not patched for that earlier pair. On boxes already fixed for 88771, Beazley reports no code execution from this DoS alone. - Community and researcher notes (Beaumont honeypot malware; Reddit username strings pointing at 213.209.159.55/
/t///v) preceded the KEV add. Citrix has not attributed those payload indicators to CVE-2026-88779. Keep them as campaign-adjacent hunts, not as vendor-proven RCE for this CVE.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| NetScaler ADC/Gateway builds before 14.1-73.41 / 13.1-64.28 (FIPS 14.1-73.41; FIPS/NDcPP 13.1-37.282) when SAML preconditions apply | Vulnerable app | T1190 | show ns version / inventory / HA peer build list | List every customer-managed ADC and Gateway, including Secure Private Access Hybrid instances. If the running build is below the fixed line for its branch and SAML is configured, upgrade to 14.1-73.41, 13.1-64.28, or the matching FIPS/NDcPP build. Preserve logs and crash dumps before the upgrade when you can. |
Config lines add authentication samlAction or add authentication samlIdPProfile | Exposure precondition | T1190 | /flash/nsconfig/ns.conf / show ns runningConfig | Grep saved and running config for add authentication samlAction and add authentication samlIdPProfile. A hit means the CVE precondition is met for that node. Record both HA peers. |
| Global Deny List signatures with Encrypted Version ≥24, Virtual patching enabled, only on 14.1-73.37–<14.1-73.41 or 13.1-64.23–<13.1-64.28 | Interim mitigation | T1190 | NetScaler Console Virtual patching status / show appfw signatures / stat denylist global AAA_REQUEST | If you cannot upgrade today and the node is in the Citrix-documented build window, enable Virtual patching in Console, confirm default signatures Encrypted Version is 24 or higher, and check stat denylist global AAA_REQUEST counters. This is a bridge. The fix remains the fixed firmware. |
Repeated nsaaad exits (community reports cite status 0x8a) followed by Pitboss restart exhaustion and appliance reboot | Crash / DoS symptom | T1499 | /var/log/ns.log, /var/log/messages, /var/core | Alert on clusters of nsaaad failures that end in Pitboss restart-limit reboot on SAML-enabled nodes. Copy /var/core and the matching ns.log window before rebuild. A crash alone is not proof of code execution. |
Oversized SAML InclusiveNamespaces PrefixList processed by nsaaad (Beazley 2026-10-04 technical note) | Exploit trigger shape | T1190 | SAML/IdP or AAA auth logs correlated with nsaaad exits | When investigating a crash window, retain the SAML request that arrived just before nsaaad died and look for an abnormal InclusiveNamespaces PrefixList. Treat that packet capture or log extract as evidence for IR, not as a public Nuclei check. |
Outbound to 213.209.159.55 (paths under /t/) or local file /v / /tmp/v / /var/tmp/v | Campaign-adjacent indicator | T1105 | Egress firewall / NetScaler outbound / filesystem | Search egress and appliance records for 213.209.159.55 and for unexpected /v under /, /tmp, or /var/tmp. Citrix has not tied these to CVE-2026-88779. A hit is a lead for the broader NetScaler campaign (including 88771 post-ex), not proof this CVE executed code. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Citrix ADC Exploitation CVE-2023-3519 watches POST paths such as /cgi/samlauth and /saml/login. It does not look for InclusiveNamespaces abuse or nsaaad crash loops. CitrixBleed 2 rules target /p/u/doAuthentication.do. |
| Elastic | None — verified | Local elastic_dr tree has no rule whose logic matches NetScaler SAML PrefixList overflow or nsaaad/Pitboss restart exhaustion for this CVE. |
| Sigma | None — verified | Emerging-threat Citrix rules cover CVE-2019-19781, CVE-2020-8193/8195, and CVE-2023-4966. None name CVE-2026-88779 or the SAML PrefixList trigger. |
Hunt hint: On each internet-facing ADC or Gateway, record show ns version and whether samlAction or samlIdPProfile is present. Pull ns.log around any reboot since Thursday 2026-10-02. If you see nsaaad dying into a Pitboss restart loop on a SAML node that is still below 14.1-73.41 / 13.1-64.28, treat that host as KEV-scope: preserve evidence, upgrade, and run the existing 88771 webshell hunts (LogonPoint/custom, httpd.conf PHP/SetHandler, WHIPSHOT/SLAPSHOT paths) because Beazley ties the reboot to re-firing that older injection on unpatched boxes. Do not stop at Global Deny List.
Sources: CISA KEV alert 2026-10-04 · CTX697174 · Citrix CTI guidance · BleepingComputer · Beazley BSL-A1216 · SecurityWeek
Status Updates
- CVE-2026-102489 (Zammad): KEV due TODAY 2026-10-05; forensic triage Yes. Session hijack to code as
zammadon 6.3.0–6.5.4. Interim build 7.2.0. Oct 3 brief. - CVE-2026-102490 (Zammad): KEV due TODAY 2026-10-05; forensic triage Yes. Local
zammadto root. No confirmed fixed build beyond moving off the affected line. Oct 3 brief. - CVE-2026-104286 (FortiMail): KEV due was 2026-10-04; forensic triage Yes. SecPod’s 2026-10-05 read of FG-IR-26-175 still lists fixed builds as upcoming (8.0.2, 7.6.7, 7.4.9; 7.2 moves to 7.4). Keep
/data/etc/ld.so.preloadandliblog.sohunts, and the IBE workaround. Oct 2 brief. - CVE-2026-61500 (Rejetto HFS): No material change. Still not CISA KEV. Keep 3.0.0–3.2.0 → ≥3.2.1,
/~/api/loginSrp1, andserver_codehunts. Oct 4 brief. - CVE-2026-88062 (OmniRoute): No material change. Version line still disputed. Keep
POST /api/acp/agentsandrequireLogin=falsehunts. Oct 4 brief. - CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due was 2026-10-03; forensic triage Yes. Confirm fixed builds and URI-encoded
j_security_checkhunts. Oct 1 brief. - CVE-2026-86950 (Apple CoreGraphics): KEV due was 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
- CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. Beazley’s 88779 note re-ties reboots to this log-injection chain on unpatched boxes. Keep LevelBlue
sec_monitor/.local_journaland Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief. - CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds. DTLS-off is temporary only for this CVE. Sep 28 brief.
- GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep
mcp≥1.30.0 / ≥2.2.0 andissuer=on unattended providers. Sep 29 brief. - CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds and
sphealth.aspxhunts. Sep 26 brief. - CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
- CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
- Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375,
GH0ST/SOUL.md, andelementor/v1/events/hunts. Elementor ≥4.3.2. Sep 28 brief.