poslední zpráva
SPOJENO AI KEV ✓ (3 z 12) EPSS 0.07 (nejvyšší)
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]
Citrix NetScaler veřejná správa US CA GB HU RO FI FR IT EU NL SE AT
CVE v události 12
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-19489 | 8.8 4.0 · NetScaler | – | 0.03 |
| CVE-2026-19490 | 9.3 4.0 · NetScaler | KEV ✓ | 0.07 |
| CVE-2026-88771 | 9.5 4.0 · NetScaler | KEV ✓ | 0.01 |
| CVE-2026-88772 | 9.5 4.0 · NetScaler | KEV ✓ | 0.01 |
| CVE-2026-887729 | – | – | – |
| CVE-2026-88773 | 9.3 4.0 · NetScaler | – | 0.00 |
| CVE-2026-887739 | – | – | – |
| CVE-2026-88774 | 7.0 4.0 · NetScaler | – | 0.00 |
| CVE-2026-88775 | 8.8 4.0 · NetScaler | – | 0.00 |
| CVE-2026-88776 | 8.8 4.0 · NetScaler | – | 0.00 |
| CVE-2026-88777 | 8.8 4.0 · NetScaler | – | 0.00 |
| CVE-2026-88778 | 8.8 4.0 · NetScaler | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.5.
Tahle CVE jsem vytáhl z širšího textu článku: CVE-2026-3055, CVE-2026-4368. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.
Jak se o tom psalo 27
-
· Palo Alto Unit 42 US
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.
-
· Cyber Centre Kanada CA
Citrix security advisory (AV26-965)
Serial number: AV26-965Date: September 28, 2026 As of September 27, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Gateway 14.1 Prior to 14.1-73.37 NetScaler ADC and NetScaler Gateway 13.1 Prior to 13.1-63.23 NetScaler ADC FIPS Prior to 14.1-73.37 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.279 On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited…
-
· zachyceno · NCSC UK GB
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
-
· NKI Maďarsko HU
Riasztás a NetScaler ADC és NetScaler Gateway termékeket érintő sérülékenységekről
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a NetScaler ADC és NetScaler Gateway termékeket érintő CVE-2026-88771 és CVE-2026-88772 azonosítójú, aktívan kihasznált kritikus sérülékenységek kapcsán. A gyártó 2026. szeptember 27-én adott ki biztonsági közleményt, amelyben megerősítette, hogy a hibákat a javítások nyilvánosságra hozatala előtt már kihasználták támadók. A CVE-2026-88771 (CVSS 9.5) egy hitelesítés nélküli, […]
-
· DNSC Rumunsko RO
ALERTĂ: Vulnerabilități critice exploatate activ în Citrix NetScaler
CONTEXT La data de 27 septembrie 2026, Citrix a publicat un buletin de securitate referitor la opt ...
-
· Rapid7 US
Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772
OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration,…
-
· BleepingComputer US
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
-
· zachyceno · NCSC-FI FI
Critical vulnerabilities in in Citrix NetScaler ADC and Citrix NetScaler Gateway
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.5, CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778, Summary: CVE-2026-88771 (CVSS: 9.5): A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS: 9.5): Memory overflow vulnerability leading to Remote…
-
· zachyceno · Sophos Threat Research GB
Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation
Categories: Threat ResearchTags: advisory, vulnerability, Citrix
-
· zachyceno · CERT-FR – alerty FR
Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)
Le 27 septembre 2026, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités qui affectent NetScaler ADC et Gateway. Parmi celles-ci, les vulnérabilités CVE-2026-88771 et CVE-2026-88772 permettent une exécution de code arbitraire à distance par un attaquant non authentifié. Ces...
-
· zachyceno · CERT-FR – avis FR
Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Citrix indique que les...
-
· CSIRT Itálie (ACN) IT
Vulnerabilità in prodotti Citrix NetScaler
Citrix ha rilasciato aggiornamenti di sicurezza per ADC e Gateway, prodotti NetScaler dedicati alla distribuzione, gestione e accesso sicuro ad applicazioni e servizi, che sanano 8 vulnerabilità, di cui 3 con gravità "critica" e 5 con gravità "alta". Tra queste si evidenziano le vulnerabilità identificate tramite CVE-2026-88771 e CVE-2026-88772, per le quali Citrix ha osservato lo sfruttamento su sistemi NetScaler non aggiornati.
-
· Cyber Centre Kanada CA
AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
Number: AL26-024Date: September 27, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…
-
· CERT-EU EU
2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.
-
· NCSC-NL NL
NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway
Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties…
-
· CERT-SE SE
Kritiska sårbarheter i Citrix NetScaler ADC and Citrix NetScaler Gateway
Citrix har publicerat information om åtta allvarliga och kritiska sårbarheter i Citrix NetScaler ADC (tidigare Citrix ADC) and Citrix NetScaler Gateway (tidigare Citrix Gateway). Två av sårbarheterna, CVE-2026-88771 och CVE-2026-88772, har fått en CVSS-klassning på 9.5 där ett ett framgångsrikt utnyttjande av sårbarheterna kan innebära oautentiserad fjärrkodsexekvering på en sårbar instans. [1]
-
· BleepingComputer US nadpis události
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]
-
· CERT.at AT
Kritische Sicherheitslücken in Citrix NetScaler ADC und NetScaler Gateway - aktiv ausgenutzt - Updates verfügbar
27. September 2026 Beschreibung In Citrix NetScaler ADC und Citrix NetScaler Gateway existieren mehrere Sicherheitslücken, darunter zwei kritische Schwachstellen, die die Ausführung von beliebigem Code ermöglichen. Laut Hersteller werden CVE-2026-88771 und CVE-2026-88772 bereits aktiv ausgenutzt. CVE-Nummer(n): CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778 CVSS v4.0 Base Scores: bis zu 9.5 (kritisch) Auswirkungen…
-
· zachyceno · CISA Advisories US
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and…
-
· zachyceno · CISA KEV US
Citrix NetScaler Improper Input Validation Vulnerability (CVE-2026-88771)
CISA added CVE-2026-88771 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-30.
-
· zachyceno · CISA KEV US
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88772)
CISA added CVE-2026-88772 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-30.
-
· Cyber Centre Kanada CA
AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489
Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…
-
· CSIRT Itálie (ACN) IT
Vulnerabilità in prodotti Citrix
Aggiornamenti di sicurezza Citrix sanano due vulnerabilità con gravità "alta" nei prodotti NetScaler ADC (precedentemente noto come Citrix ADC) e NetScaler Gateway (precedentemente noto come Citrix Gateway).
-
· NCSC-NL NL
NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway
Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep. Deze fout in de geheugenallocatie kan leiden tot onvoorspelbaar gedrag of een denial of service, waardoor de normale werking van het systeem verstoord kan worden. De kwetsbaarheid met kenmerk CVE-2026-19490 maakt het…
-
· zachyceno · NCSC-FI FI
Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.3, CVEs: CVE-2026-19489, CVE-2026-19490, Summary: Citrix on julkaissut Netscaler ADC ja Gateway -tuotteisiin useita kriittisiä haavoittuvuuksia, jotka mahdollistavat todennuksen ohittamisen, saatavuuskatkoksen taikka muun arvaamattoman toiminnan ympäristössä. Organisaatioiden tulisi asentaa valmistajan julkaisemat korjauspäivitykset viipymättä. - Haavoittuvuus: 23/2026 - Tunnisteet: CVE-2026-19489 & CVE…
-
· zachyceno · CERT-FR – avis FR
Multiples vulnérabilités dans les produits Citrix (20 août 2026)
De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
-
· Cyber Centre Kanada CA
Citrix security advisory (AV26-833)
Serial Number: AV26-833Date: August 19, 2026 As of August 19, 2026, NetScaler is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to or equal to 13.1-63.21 Version 14.1 prior to or equal to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…