字号 ·· | 护眼
罗塞塔简报

Citrix修复两个被积极利用的NetScaler关键远程代码执行漏洞Citrix修复两个被积极利用的NetScaler关键远程代码执行漏洞

点「原文对照」整页切到原文,或双击某段只看那段的原文。

Citrix 修复了两个正在被积极利用的关键 NetScaler 零日 RCE 漏洞。

Citrix Patches Two Critical NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation Citrix has confirmed and patched two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. Both flaws carry a severity score of 9.5 and were exploited as zero-days. CVE-2026-88771 stems from improper input validation, while CVE-2026-88772 is a memory overflow flaw affecting DTLS-enabled deployments. Before the official security bulletin (CTX697096), the Dutch National Cyber Security Center (NCSC-NL) and other agencies privately warned organizations to shut down devices. Citrix has released security updates for multiple versions, including 13.1 and 14.1, and noted that Cloud Software Group is updating Citrix-managed cloud services.

Citrix 已确认并修补了 NetScaler ADC 和 NetScaler Gateway 设备中的两个关键远程代码执行 (RCE) 漏洞,分别编号为 CVE-2026-88771 和 CVE-2026-88772。

Citrix Patches Two Critical NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation Citrix has confirmed and patched two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. Both flaws carry a severity score of 9.5 and were exploited as zero-days. CVE-2026-88771 stems from improper input validation, while CVE-2026-88772 is a memory overflow flaw affecting DTLS-enabled deployments. Before the official security bulletin (CTX697096), the Dutch National Cyber Security Center (NCSC-NL) and other agencies privately warned organizations to shut down devices. Citrix has released security updates for multiple versions, including 13.1 and 14.1, and noted that Cloud Software Group is updating Citrix-managed cloud services.

这两个漏洞的严重性评分均为 9.5,且均作为零日漏洞被利用。

Citrix Patches Two Critical NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation Citrix has confirmed and patched two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. Both flaws carry a severity score of 9.5 and were exploited as zero-days. CVE-2026-88771 stems from improper input validation, while CVE-2026-88772 is a memory overflow flaw affecting DTLS-enabled deployments. Before the official security bulletin (CTX697096), the Dutch National Cyber Security Center (NCSC-NL) and other agencies privately warned organizations to shut down devices. Citrix has released security updates for multiple versions, including 13.1 and 14.1, and noted that Cloud Software Group is updating Citrix-managed cloud services.

CVE-2026-88771 源于不当的输入验证,而 CVE-2026-88772 是影响启用 DTLS 部署的内存溢出缺陷。

Citrix Patches Two Critical NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation Citrix has confirmed and patched two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. Both flaws carry a severity score of 9.5 and were exploited as zero-days. CVE-2026-88771 stems from improper input validation, while CVE-2026-88772 is a memory overflow flaw affecting DTLS-enabled deployments. Before the official security bulletin (CTX697096), the Dutch National Cyber Security Center (NCSC-NL) and other agencies privately warned organizations to shut down devices. Citrix has released security updates for multiple versions, including 13.1 and 14.1, and noted that Cloud Software Group is updating Citrix-managed cloud services.

在官方安全公告 (CTX697096) 发布之前,荷兰国家网络安全中心 (NCSC-NL) 和其他机构曾私下警告组织关闭设备。

Citrix Patches Two Critical NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation Citrix has confirmed and patched two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. Both flaws carry a severity score of 9.5 and were exploited as zero-days. CVE-2026-88771 stems from improper input validation, while CVE-2026-88772 is a memory overflow flaw affecting DTLS-enabled deployments. Before the official security bulletin (CTX697096), the Dutch National Cyber Security Center (NCSC-NL) and other agencies privately warned organizations to shut down devices. Citrix has released security updates for multiple versions, including 13.1 and 14.1, and noted that Cloud Software Group is updating Citrix-managed cloud services.

Citrix 已为多个版本发布了安全更新,包括 13.1 和 14.1,并指出 Cloud Software Group 正在更新 Citrix 托管的云服务。

Citrix Patches Two Critical NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation Citrix has confirmed and patched two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, tracked as CVE-2026-88771 and CVE-2026-88772. Both flaws carry a severity score of 9.5 and were exploited as zero-days. CVE-2026-88771 stems from improper input validation, while CVE-2026-88772 is a memory overflow flaw affecting DTLS-enabled deployments. Before the official security bulletin (CTX697096), the Dutch National Cyber Security Center (NCSC-NL) and other agencies privately warned organizations to shut down devices. Citrix has released security updates for multiple versions, including 13.1 and 14.1, and noted that Cloud Software Group is updating Citrix-managed cloud services.