注意喚起: NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 (更新)
Cybersecurity Classified by Officially
MandiantおよびGTIGは、CVE-2026-88772を悪用する攻撃に関して、侵害有無を確認するための情報や侵害痕跡(IOC)などを公開しています。
MandiantおよびGTIGは、確認した侵害事例において、攻撃者がWebサーバーの設定変更、Webシェルの設置、"/bin/sh"へのSUID権限の設定など、侵害後のアクセス維持を目的とした活動を行っていたことを報告しています。
MandiantおよびGTIGは、侵害有無を確認するため、既存のログや設定ファイルなどを調査することを推奨しています。確認事項として、次のような情報が挙げられています。
- Webサーバーの設定ファイル("/etc/httpd.conf")の不審な変更
- "/tmp/.uxdport"および"/tmp/.uxdlock"などの不審なファイル
本脆弱性の影響を受ける製品を利用している場合は、MandiantおよびGTIG、ならびに開発者が提供する最新の情報を参考に、本脆弱性を悪用する攻撃の影響を受けていないか調査してください。
Mandiant / Google Threat Intelligence Group
This is an extract. The publication continues at the source.
Read the original at the source: https://www.jpcert.or.jp/at/2026/at260029.html
Officially imported this from JPCERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on Titled: “注意喚起: NetScaler ADCおよびNetScaler Gatewayにおける複数の脆弱性(CVE-2026-88771、CVE-2026-88772等)に関する注意喚起 (公開)”
Provenance
- Organization
- JPCERT Coordination Center — imported from official source
- Official source
- https://www.jpcert.or.jp/rss/jpcert.rdf RSS
- Imported
- September 28, 2026 09:00
- Versions
- 2 recorded
- Identity
https://www.jpcert.or.jp/at/2026/at260029.html