攻击者正在利用 Citrix NetScaler ADC 和 NetScaler Gateway 中的两个关键安全漏洞。这些设备被企业用于为员工提供对内部网络的远程访问功能。Citrix 在周日发布的一份安全公告中确认了这些攻击事件,并提供了相应的修复补丁。值得注意的是,这两个漏洞在补丁发布之前就已经被攻击者利用过了。
Attackers are exploiting two critical flaws in Citrix NetScaler ADC and NetScaler Gateway. Companies use the devices to give staff remote access to internal networks. Citrix confirmed the attacks in a security bulletin on Sunday and released fixes. Both flaws were exploited before a patch existed.
Citrix 表示:“在未安装任何安全补丁的 NetScaler 系统中,已经观察到了针对 CVE-2026-88771 和 CVE-2026-88772 漏洞的攻击行为。”
“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said.
CVE-2026-88771 漏洞允许攻击者在无需登录的情况下执行命令;该漏洞影响所有版本的 NetScaler ADC 和 NetScaler Gateway(包括默认配置的系统)。CVE-2026-88772 漏洞属于内存溢出类型,可能导致远程代码执行或系统崩溃;该漏洞的利用需要依赖名为“DTLS”的安全设置,而该设置在 VPN 服务器上通常是开启的。这两个漏洞的严重性等级均为 9.5 分(满分 10 分)。
CVE-2026-88771 lets an attacker run commands without logging in. It affects all NetScaler ADC and Gateway deployments, including the default setup. CVE-2026-88772 is a memory overflow that can lead to remote code execution or a crash. It needs a setting called DTLS, which is on by default on VPN servers. Both score 9.5 out of 10 for severity. The bulletin covers eight flaws in total. Fixed versions are 14.1-73.37 and 13.1-64.23, plus matching FIPS builds. Citrix is upgrading the cloud services it manages itself.
此次安全公告共涵盖了 8 个安全漏洞;已修复的版本号为 14.1-73.37 和 13.1-64.23,同时还包括相应的 FIPS 构建版本。Citrix 正在对其管理的云服务进行升级。
Government warnings The US Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its list of known exploited vulnerabilities on Sunday. It gave federal civilian agencies until 30 September to fix them.
政府警告:美国网络安全与基础设施安全局(CISA)已于周日将这两个漏洞列入已知被利用的漏洞列表,并要求联邦民用机构在 9 月 30 日之前完成修复。CISA 在一份警告中表示:“我们已收到相关报告及合作伙伴提供的威胁情报,证实攻击者正在全球范围内积极利用这些漏洞。”该机构还提醒各组织在应用补丁前务必检查系统是否已被入侵,因为补丁的安装可能会清除重要的取证线索。根据荷兰国家网络安全中心(NCSC-NL)的建议,CVE-2026-88771 漏洞会导致攻击者完全控制目标网关,并直接访问其背后的网络。
Government warnings The US Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its list of known exploited vulnerabilities on Sunday. It gave federal civilian agencies until 30 September to fix them. “CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally,” the agency said in an alert. CISA urged organisations to check for signs of compromise before patching, because updates can erase forensic evidence. The first flaw gives attackers full control of the gateway and direct access to the network behind it. That is according to the Dutch National Cyber Security Centre (NCSC-NL) in its advisory.
补丁发布前的警告:在 Citrix 公开这一消息之前,管理员们在 Reddit 上表示,一些 IT 供应商已要求他们关闭自家的 NetScaler 设备。据 Lawrence Abrams 为 BleepingComputer 报道,荷兰国家网络安全中心(NCSC-NL)也发布了一份预先通知,其中提到 Citrix 在调查客户遇到的安全问题时发现了这些漏洞,并根据《网络韧性法案》(Cyber Resilience Act)向欧盟通报了相关情况。不过,NCSC-NL 拒绝向 BleepingComputer 确认这一通知的真实性。
Warnings before the patch Before Citrix went public, administrators said on Reddit that IT suppliers had told them to shut their NetScaler devices down. A pre-notification from NCSC-NL was also circulating, Lawrence Abrams reported for BleepingComputer. It said Citrix found the flaws while investigating incidents at customers and notified the EU under the Cyber Resilience Act. NCSC-NL declined to confirm the notice to BleepingComputer.
安全研究员 Kevin Beaumont 指出,这些攻击活动已经持续了一个多月,他认为攻击者“很可能是受某个国家支持的”。Citrix 目前尚未公开指出这些攻击者的真实身份。
The attacks have run all month, security researcher Kevin Beaumont wrote, describing the attackers as “probably nation state aligned”. Citrix has not said who is behind them.
本月早些时候,思科(Cisco)曾警告称,攻击者正在利用其 Identity Services Engine 中的一个最高严重级别的安全漏洞;微软在九月份发布的更新修复了这两个零日漏洞(即那些尚未被公开的安全漏洞)。
Earlier this month, Cisco warned that attackers were exploiting a maximum-severity flaw in its Identity Services Engine. Microsoft’s September updates fixed two zero-days.