注意喚起: NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 (更新)

Imported from official source

Cybersecurity Classified by Officially

MandiantおよびGTIGは、CVE-2026-88772を悪用する攻撃に関して、侵害有無を確認するための情報や侵害痕跡(IOC)などを公開しています。

MandiantおよびGTIGは、確認した侵害事例において、攻撃者がWebサーバーの設定変更、Webシェルの設置、"/bin/sh"へのSUID権限の設定など、侵害後のアクセス維持を目的とした活動を行っていたことを報告しています。

MandiantおよびGTIGは、侵害有無を確認するため、既存のログや設定ファイルなどを調査することを推奨しています。確認事項として、次のような情報が挙げられています。

- Webサーバーの設定ファイル("/etc/httpd.conf")の不審な変更

- "/tmp/.uxdport"および"/tmp/.uxdlock"などの不審なファイル

本脆弱性の影響を受ける製品を利用している場合は、MandiantおよびGTIG、ならびに開発者が提供する最新の情報を参考に、本脆弱性を悪用する攻撃の影響を受けていないか調査してください。

Mandiant / Google Threat Intelligence Group

This is an extract. The publication continues at the source.

Read the original at the source: https://www.jpcert.or.jp/at/2026/at260029.html

Officially imported this from JPCERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on Titled: “注意喚起: NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 (公開)”

Provenance

Organization
JPCERT Coordination Center — imported from official source
Official source
https://www.jpcert.or.jp/rss/jpcert.rdf RSS
Imported
September 28, 2026 09:00
Versions
2 recorded
Identity
https://www.jpcert.or.jp/at/2026/at260029.html

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.