Citrix NetScaler SAML DoS (CVE-2026-88779): crash preceded by SAML auth burst

Detects potential exploitation of a SAML-related vulnerability in Citrix NetScaler appliances by correlating a surge in SAML authentication traffic to Gateway/AAA endpoints followed by application crashes or core dumps on the device. This behavioral pattern is indicative of a crash-inducing exploitation attempt targeting SAML processing.