← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO AI KEV ✓ (3 z 12) EPSS 0.07 (nejvyšší)

Citrix admins warned to shut down NetScalers over 2 exploited zero-days

Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]

Číst originál na BleepingComputer →

27 zpráv z 18 zdrojů · první CZ · EN/orig

Citrix NetScaler veřejná správa US CA GB HU RO FI FR IT EU NL SE AT

tg: varování tg: zneužíváno tg: zranitelnost tg: regulace tp: identita

CVE v události 12

CVEhodnoceníKEVEPSS
CVE-2026-19489 8.8 4.0 · NetScaler – 0.03
CVE-2026-19490 9.3 4.0 · NetScaler KEV ✓ 0.07
CVE-2026-88771 9.5 4.0 · NetScaler KEV ✓ 0.01
CVE-2026-88772 9.5 4.0 · NetScaler KEV ✓ 0.01
CVE-2026-887729 – – –
CVE-2026-88773 9.3 4.0 · NetScaler – 0.00
CVE-2026-887739 – – –
CVE-2026-88774 7.0 4.0 · NetScaler – 0.00
CVE-2026-88775 8.8 4.0 · NetScaler – 0.00
CVE-2026-88776 8.8 4.0 · NetScaler – 0.00
CVE-2026-88777 8.8 4.0 · NetScaler – 0.00
CVE-2026-88778 8.8 4.0 · NetScaler – 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.5.

Tahle CVE jsem vytáhl z širšího textu článku: CVE-2026-3055, CVE-2026-4368. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.

Jak se o tom psalo 27

  1. · Palo Alto Unit 42 US

    Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

    Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.

  2. · Cyber Centre Kanada CA

    Citrix security advisory (AV26-965)

    Serial number: AV26-965Date: September 28, 2026 As of September 27, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Gateway 14.1 Prior to 14.1-73.37 NetScaler ADC and NetScaler Gateway 13.1 Prior to 13.1-63.23 NetScaler ADC FIPS Prior to 14.1-73.37 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.279 On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited…

  3. · zachyceno · NCSC UK GB

    Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

    The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

  4. · NKI Maďarsko HU

    Riasztás a NetScaler ADC és NetScaler Gateway termékeket érintő sérülékenységekről

    A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a NetScaler ADC és NetScaler Gateway termékeket érintő CVE-2026-88771 és CVE-2026-88772 azonosítójú, aktívan kihasznált kritikus sérülékenységek kapcsán. A gyártó 2026. szeptember 27-én adott ki biztonsági közleményt, amelyben megerősítette, hogy a hibákat a javítások nyilvánosságra hozatala előtt már kihasználták támadók. A CVE-2026-88771 (CVSS 9.5) egy hitelesítés nélküli, […]

  5. · DNSC Rumunsko RO

    ALERTĂ: Vulnerabilități critice exploatate activ în Citrix NetScaler

    CONTEXT La data de 27 septembrie 2026, Citrix a publicat un buletin de securitate referitor la opt ...

  6. · Rapid7 US

    Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

    OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration,…

  7. · BleepingComputer US

    CISA orders feds to patch exploited Citrix flaws by Wednesday

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

  8. · zachyceno · NCSC-FI FI

    Critical vulnerabilities in in Citrix NetScaler ADC and Citrix NetScaler Gateway

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.5, CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778, Summary: CVE-2026-88771 (CVSS: 9.5): A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS: 9.5): Memory overflow vulnerability leading to Remote…

  9. · zachyceno · Sophos Threat Research GB

    Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation

    Categories: Threat ResearchTags: advisory, vulnerability, Citrix

  10. · zachyceno · CERT-FR – alerty FR

    Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

    Le 27 septembre 2026, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités qui affectent NetScaler ADC et Gateway. Parmi celles-ci, les vulnérabilités CVE-2026-88771 et CVE-2026-88772 permettent une exécution de code arbitraire à distance par un attaquant non authentifié. Ces...

  11. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Citrix indique que les...

  12. · CSIRT Itálie (ACN) IT

    Vulnerabilità in prodotti Citrix NetScaler

    Citrix ha rilasciato aggiornamenti di sicurezza per ADC e Gateway, prodotti NetScaler dedicati alla distribuzione, gestione e accesso sicuro ad applicazioni e servizi, che sanano 8 vulnerabilità, di cui 3 con gravità "critica" e 5 con gravità "alta". Tra queste si evidenziano le vulnerabilità identificate tramite CVE-2026-88771 e CVE-2026-88772, per le quali Citrix ha osservato lo sfruttamento su sistemi NetScaler non aggiornati.

  13. · Cyber Centre Kanada CA

    AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772

    Number: AL26-024Date: September 27, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

  14. · CERT-EU EU

    2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

    On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

  15. · NCSC-NL NL

    NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

    Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties…

  16. · CERT-SE SE

    Kritiska sårbarheter i Citrix NetScaler ADC and Citrix NetScaler Gateway

    Citrix har publicerat information om åtta allvarliga och kritiska sårbarheter i Citrix NetScaler ADC (tidigare Citrix ADC) and Citrix NetScaler Gateway (tidigare Citrix Gateway). Två av sårbarheterna, CVE-2026-88771 och CVE-2026-88772, har fått en CVSS-klassning på 9.5 där ett ett framgångsrikt utnyttjande av sårbarheterna kan innebära oautentiserad fjärrkodsexekvering på en sårbar instans. [1]

  17. · BleepingComputer US nadpis události

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]

  18. · CERT.at AT

    Kritische Sicherheitslücken in Citrix NetScaler ADC und NetScaler Gateway - aktiv ausgenutzt - Updates verfügbar

    27. September 2026 Beschreibung In Citrix NetScaler ADC und Citrix NetScaler Gateway existieren mehrere Sicherheitslücken, darunter zwei kritische Schwachstellen, die die Ausführung von beliebigem Code ermöglichen. Laut Hersteller werden CVE-2026-88771 und CVE-2026-88772 bereits aktiv ausgenutzt. CVE-Nummer(n): CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778 CVSS v4.0 Base Scores: bis zu 9.5 (kritisch) Auswirkungen…

  19. · zachyceno · CISA Advisories US

    Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

    CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and…

  20. · zachyceno · CISA KEV US

    Citrix NetScaler Improper Input Validation Vulnerability (CVE-2026-88771)

    CISA added CVE-2026-88771 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-30.

  21. · zachyceno · CISA KEV US

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88772)

    CISA added CVE-2026-88772 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-30.

  22. · Cyber Centre Kanada CA

    AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

    Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…

  23. · CSIRT Itálie (ACN) IT

    Vulnerabilità in prodotti Citrix

    Aggiornamenti di sicurezza Citrix sanano due vulnerabilità con gravità "alta" nei prodotti NetScaler ADC (precedentemente noto come Citrix ADC) e NetScaler Gateway (precedentemente noto come Citrix Gateway).

  24. · NCSC-NL NL

    NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway

    Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep. Deze fout in de geheugenallocatie kan leiden tot onvoorspelbaar gedrag of een denial of service, waardoor de normale werking van het systeem verstoord kan worden. De kwetsbaarheid met kenmerk CVE-2026-19490 maakt het…

  25. · zachyceno · NCSC-FI FI

    Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.3, CVEs: CVE-2026-19489, CVE-2026-19490, Summary: Citrix on julkaissut Netscaler ADC ja Gateway -tuotteisiin useita kriittisiä haavoittuvuuksia, jotka mahdollistavat todennuksen ohittamisen, saatavuuskatkoksen taikka muun arvaamattoman toiminnan ympäristössä. Organisaatioiden tulisi asentaa valmistajan julkaisemat korjauspäivitykset viipymättä. - Haavoittuvuus: 23/2026 - Tunnisteet: CVE-2026-19489 & CVE…

  26. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Citrix (20 août 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

  27. · Cyber Centre Kanada CA

    Citrix security advisory (AV26-833)

    Serial Number: AV26-833Date: August 19, 2026 As of August 19, 2026, NetScaler is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to or equal to 13.1-63.21 Version 14.1 prior to or equal to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…