NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等)

Imported from official source

Announcement

NetScaler ADC(旧Citrix ADC)およびNetScaler Gateway(旧Citrix Gateway)はネットワークを構築するためのアプライアンス製品です。

これらの製品において、複数の脆弱性(CVE-2026-88771、CVE-2026-88772、CVE-2026-88773、CVE-2026-88774、CVE-2026-88775、CVE-2026-88776、CVE-2026-88777、CVE-2026-88778)が確認されています。

CVE-2026-88771とCVE-2026-88772では、脆弱性を悪用した攻撃が確認されており、今後被害が拡大するおそれがあるため、早急にアップデートを実施してください。これらの脆弱性を悪用された場合、遠隔の第三者により任意のコードが実行されたり、サービス運用妨害(DoS)の被害を受ける可能性があります。
なお、CISA(脚注1)の情報によれば、CVE-2026-88771とCVE-2026-88772について世界中で脅威アクターが積極的に悪用しているとの報告・情報があるとのことです。

製品開発者は、脆弱性の成立条件を満たすかどうかの確認方法についてウェブサイト上で案内しています。公開している手順に従い、確認してください。また、製品開発者は、NetScaler Consoleを通じて侵害指標情報(Indicators of Compromise)を提供しているとのことです。

  • Citrix NetScaler ADCおよびCitrix NetScaler Gateway 14.1-73.37 より前のバージョンの14.1系
  • Citrix NetScaler ADCおよびCitrix NetScaler Gateway 13.1-64.23 より前のバージョンの13.1系
  • Citrix NetScaler ADC FIPS :14.1-73.37 FIPS より前のバージョン
  • Citrix NetScaler ADC FIPS and NDcPP:13.1-37.279 より前のバージョン
  • なお、CVE-2026-88772 については、DTLS 設定が有効であることが条件となるとのことです。VPN仮想サーバーではDTLSがデフォルトで有効となるとのことです。

    開発者が提供する情報をもとに、最新版へアップデートしてください。開発者は、本脆弱性を修正した次のバージョンをリリースしています。

  • NetScaler ADCおよびNetScaler Gateway 14.1-73.37あるいはそれ以降
  • NetScaler ADCおよびNetScaler Gateway 13.1-64.23あるいはそれ以降の 13.1 系のバージョン
  • NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS あるいはそれ以降の 14.1-FIPS 系のバージョン
  • NetScaler ADC 13.1-FIPSおよび13.1-NDcPP 13.1.37.279あるいはそれ以降の 13.1-FIPS および13.1-NDcPP系のバージョン
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html

    Officially imported this from Information-technology Promotion Agency (IPA)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Information-technology Promotion Agency (IPA) — imported from official source
    Official source
    https://www.ipa.go.jp/security/alert-rss.rdf RSS
    Imported
    October 03, 2026 20:39
    Versions
    1 recorded
    Identity
    https://www.ipa.go.jp/security/security-alert/2026/alert20260928.html

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.