2026年9月28日星期一

Citrix Products Multiple Vulnerabilities

Citrix Products Multiple Vulnerabilities

Release Date: 28 Sep 2026

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.

 

Note:

CVE-2026-88771 and CVE-2026-88772 are being exploited in the wild. CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Hence, the risk level is rated as Extremely High Risk.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • NetScaler ADC and  NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • NetScaler ADC and  NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link


沒有留言:

發佈留言

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期 : 2026 年 09 月 29 日 於 Apache Tomcat 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制及資料篡改。 影響 阻斷服務 篡改 繞過...