← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO AI KEV ✓ (3 z 10) EPSS 0.07 (nejvyšší)

Citrix admins warned to shut down NetScalers over 2 exploited zero-days

Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]

Číst originál na BleepingComputer →

20 zpráv z 12 zdrojů · první CZ · EN/orig

Citrix veřejná správa US FI FR IT CA EU NL SE AT

tg: varování tg: zneužíváno tg: zranitelnost tg: regulace tp: identita

CVE v události 10

CVEhodnoceníKEVEPSS
CVE-2026-19489 8.8 4.0 · NetScaler – 0.03
CVE-2026-19490 9.3 4.0 · NetScaler KEV ✓ 0.07
CVE-2026-88771 9.5 4.0 · NetScaler KEV ✓ –
CVE-2026-88772 9.5 4.0 · NetScaler KEV ✓ –
CVE-2026-88773 9.3 4.0 · NetScaler – –
CVE-2026-88774 7.0 4.0 · NetScaler – –
CVE-2026-88775 8.8 4.0 · NetScaler – –
CVE-2026-88776 – – –
CVE-2026-88777 – – –
CVE-2026-88778 – – –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.5.

Tahle CVE jsem vytáhl z širšího textu článku: CVE-2026-3055, CVE-2026-4368. Neukazuju u nich proto fakta z katalogů výše, a to preventivně, protože článek se na ně mohl jen odkazovat, třeba jako na starší kauzu.

Jak se o tom psalo 20

  1. · BleepingComputer US

    CISA orders feds to patch exploited Citrix flaws by Wednesday

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

  2. · zachyceno · NCSC-FI FI

    Critical vulnerabilities in in Citrix NetScaler ADC and Citrix NetScaler Gateway

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.5, CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778, Summary: CVE-2026-88771 (CVSS: 9.5): A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 (CVSS: 9.5): Memory overflow vulnerability leading to Remote…

  3. · zachyceno · CERT-FR – alerty FR

    Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

    Le 27 septembre 2026, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités qui affectent NetScaler ADC et Gateway. Parmi celles-ci, les vulnérabilités CVE-2026-88771 et CVE-2026-88772 permettent une exécution de code arbitraire à distance par un attaquant non authentifié. Ces...

  4. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Citrix indique que les...

  5. · CSIRT Itálie (ACN) IT

    Vulnerabilità in prodotti Citrix NetScaler

    Citrix ha rilasciato aggiornamenti di sicurezza per ADC e Gateway, prodotti NetScaler dedicati alla distribuzione, gestione e accesso sicuro ad applicazioni e servizi, che sanano 8 vulnerabilità, di cui 3 con gravità "critica" e 5 con gravità "alta". Tra queste si evidenziano le vulnerabilità identificate tramite CVE-2026-88771 e CVE-2026-88772, per le quali Citrix ha osservato lo sfruttamento su sistemi NetScaler non aggiornati.

  6. · Cyber Centre Kanada CA

    AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772

    Number: AL26-024Date: September 27, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

  7. · CERT-EU EU

    2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

    On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

  8. · NCSC-NL NL

    NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

    Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties…

  9. · CERT-SE SE

    Kritiska sårbarheter i Citrix NetScaler ADC and Citrix NetScaler Gateway

    Citrix har publicerat information om åtta allvarliga och kritiska sårbarheter i Citrix NetScaler ADC (tidigare Citrix ADC) and Citrix NetScaler Gateway (tidigare Citrix Gateway). Två av sårbarheterna, CVE-2026-88771 och CVE-2026-88772, har fått en CVSS-klassning på 9.5 där ett ett framgångsrikt utnyttjande av sårbarheterna kan innebära oautentiserad fjärrkodsexekvering på en sårbar instans. [1]

  10. · BleepingComputer US nadpis události

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]

  11. · CERT.at AT

    Kritische Sicherheitslücken in Citrix NetScaler ADC und NetScaler Gateway - aktiv ausgenutzt - Updates verfügbar

    27. September 2026 Beschreibung In Citrix NetScaler ADC und Citrix NetScaler Gateway existieren mehrere Sicherheitslücken, darunter zwei kritische Schwachstellen, die die Ausführung von beliebigem Code ermöglichen. Laut Hersteller werden CVE-2026-88771 und CVE-2026-88772 bereits aktiv ausgenutzt. CVE-Nummer(n): CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, CVE-2026-88778 CVSS v4.0 Base Scores: bis zu 9.5 (kritisch) Auswirkungen…

  12. · zachyceno · CISA Advisories US

    Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

    CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778. CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and…

  13. · zachyceno · CISA KEV US

    Citrix NetScaler Improper Input Validation Vulnerability (CVE-2026-88771)

    CISA added CVE-2026-88771 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-30.

  14. · zachyceno · CISA KEV US

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88772)

    CISA added CVE-2026-88772 to the Known Exploited Vulnerabilities catalog. Affected product: Citrix NetScaler. Remediation due date: 2026-09-30.

  15. · Cyber Centre Kanada CA

    AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

    Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…

  16. · CSIRT Itálie (ACN) IT

    Vulnerabilità in prodotti Citrix

    Aggiornamenti di sicurezza Citrix sanano due vulnerabilità con gravità "alta" nei prodotti NetScaler ADC (precedentemente noto come Citrix ADC) e NetScaler Gateway (precedentemente noto come Citrix Gateway).

  17. · NCSC-NL NL

    NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway

    Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep. Deze fout in de geheugenallocatie kan leiden tot onvoorspelbaar gedrag of een denial of service, waardoor de normale werking van het systeem verstoord kan worden. De kwetsbaarheid met kenmerk CVE-2026-19490 maakt het…

  18. · zachyceno · NCSC-FI FI

    Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.3, CVEs: CVE-2026-19489, CVE-2026-19490, Summary: Citrix on julkaissut Netscaler ADC ja Gateway -tuotteisiin useita kriittisiä haavoittuvuuksia, jotka mahdollistavat todennuksen ohittamisen, saatavuuskatkoksen taikka muun arvaamattoman toiminnan ympäristössä. Organisaatioiden tulisi asentaa valmistajan julkaisemat korjauspäivitykset viipymättä. - Haavoittuvuus: 23/2026 - Tunnisteet: CVE-2026-19489 & CVE…

  19. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Citrix (20 août 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Citrix. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

  20. · Cyber Centre Kanada CA

    Citrix security advisory (AV26-833)

    Serial Number: AV26-833Date: August 19, 2026 As of August 19, 2026, NetScaler is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to or equal to 13.1-63.21 Version 14.1 prior to or equal to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.…