据说,死亡和税收是人生中唯一可以确定的“必然之事”。或许现在应该把那些利用 Citrix 公司 NetScaler 应用程序交付控制器及网关产品中新发现的严重安全漏洞的攻击者,也加入到这个“不可避免的威胁列表”中。周日,Citrix 公司发布了一份安全公告,警告用户存在八处安全漏洞(CVE)。其中最严重的两个漏洞(CVE-2026-88771 和 CVE-2026-88772)的 CVSS 评分高达 9.5 分,属于“严重级”漏洞。CVE-2026-88771 允许攻击者远程执行代码;CVE-2026-88772 则是一种内存溢出漏洞,可能导致远程代码执行或系统服务中断。Reddit 上有一个帖子称,至少有一家 Citrix 的渠道合作伙伴在周六就已经知晓了这些漏洞,并敦促用户立即将他们的 NetScaler 设备关闭(这一建议比 Citrix 公司正式发布公告早了一天)。Citrix 表示,这两个漏洞目前已经遭到攻击。鉴于这一严峻形势,美国网络安全与基础设施安全局(CISA)也在周日发布了警报,称他们“收到了相关报告及合作伙伴提供的威胁情报,证实攻击者正在全球范围内积极利用这些漏洞”。警报中还指出:“由于更新 Citrix NetScaler 设备的过程可能较为复杂且需要停机时间,CISA 发布此警报旨在帮助各组织评估自身面临的风险、确定优先级并采取相应的缓解措施。”这些风险管理措施还需要考虑第三处严重漏洞(CVE-2026-88773,评分 9.3 分)——该漏洞允许攻击者通过 HTTP 请求进行恶意操作,从而绕过前端服务器的安全防护机制。另外还有三处漏洞属于内存溢出类型(评分 8.8 分),可能导致 NetScaler 设备运行不稳定;另一处漏洞与 TCP 初始序列号预测机制有关;还有一处漏洞是由于 HTTP URL 表达式使用不当而导致的系统功能绕过漏洞(评分 7.0 分)。
Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – are rated critical with 9.5 CVSS scores. CVE-2026-88771 allows remote code execution and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure. Citrix has observed that both vulnerabilities are already under attack. That sad fact saw the United States’ Cybersecurity and Infrastructure Security Agency on Sunday issue an alert because it too “has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.” “Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities,” the alert adds. Those risk management efforts will also have to consider a third critical vulnerability, the 9.3-rated CVE-2026-88773, allows HTTP request smuggling – an attack technique that can bypass security controls installed on front-end servers. Three of the bugs are 8.8-rated memory overflow bugs that can make NetScaler appliances unstable. Another 8.8-rated bug relates to TCP Initial Sequence Number prediction, and there’s also a 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage. Citrix’s post explains how to detect if your NetScaler needs a fix, and which patches to apply. Thankfully, the company has already created OS refreshes that contain the fixes. NetScaler is notoriously buggy. In March 2026, Citrix revealed critical vulns that were quickly attacked. The same thing happened in 2025, twice, and also in 2023. Flaws in NetScaler appeared in the annual most-exploited bugs list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023. Despite NetScaler’s long history of holes, some users choose not to patch the product. That’s fair enough, given that it’s not always easy to find a change window in which to install a patch. But it’s hard to explain given NetScaler is nearly always under attack, and security vendors’ increasing efforts to create compensating controls that make it possible to use flawed devices safely without patches. ®
Citrix在这篇文章中介绍了如何判断自己的NetScaler设备是否需要修复,以及应该应用哪些补丁。幸运的是,该公司已经发布了包含这些修复内容的操作系统更新版本。NetScaler以其频繁出现漏洞的问题而闻名。2026年3月,Citrix公开了多个严重的安全漏洞,这些漏洞很快就被黑客利用了;类似的情况在2025年也发生过两次,2023年也同样如此。从2020年到2023年,NetScaler的漏洞一直被列入“五眼联盟”(Five Eyes Alliance)各网络安全机构发布的“年度最常被利用的漏洞列表”中。尽管NetScaler存在诸多安全问题,但仍有一些用户选择不为其安装补丁。这也可以理解——因为找到合适的时机来安装补丁确实并不容易。然而,考虑到NetScaler几乎一直处于被攻击的状态,以及安全厂商不断努力开发新的安全机制(使得用户可以在不安装补丁的情况下安全地使用这些有漏洞的设备),这种选择就显得难以理解了。
Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – are rated critical with 9.5 CVSS scores. CVE-2026-88771 allows remote code execution and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. A Reddit thread contains an allegation that at least one Citrix channel partner knew of these flaws on Saturday and urged users to take their NetScalers offline - a day before Citrix's disclosure. Citrix has observed that both vulnerabilities are already under attack. That sad fact saw the United States’ Cybersecurity and Infrastructure Security Agency on Sunday issue an alert because it too “has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally.” “Because updating Citrix NetScaler appliances can be complex and may require downtime, CISA is issuing this Alert to help organizations assess exposure, prioritize mitigation, and account for these vulnerabilities into their risk-management activities,” the alert adds. Those risk management efforts will also have to consider a third critical vulnerability, the 9.3-rated CVE-2026-88773, allows HTTP request smuggling – an attack technique that can bypass security controls installed on front-end servers. Three of the bugs are 8.8-rated memory overflow bugs that can make NetScaler appliances unstable. Another 8.8-rated bug relates to TCP Initial Sequence Number prediction, and there’s also a 7.0-rated feature policy bypass due to improper HTTP URL-based expression usage. Citrix’s post explains how to detect if your NetScaler needs a fix, and which patches to apply. Thankfully, the company has already created OS refreshes that contain the fixes. NetScaler is notoriously buggy. In March 2026, Citrix revealed critical vulns that were quickly attacked. The same thing happened in 2025, twice, and also in 2023. Flaws in NetScaler appeared in the annual most-exploited bugs list published by the cybersecurity agencies of the Five Eyes alliance from 2020 to 2023. Despite NetScaler’s long history of holes, some users choose not to patch the product. That’s fair enough, given that it’s not always easy to find a change window in which to install a patch. But it’s hard to explain given NetScaler is nearly always under attack, and security vendors’ increasing efforts to create compensating controls that make it possible to use flawed devices safely without patches. ®