{"schema":"hottub-news/story/v1","story":"st_2wujuu3lbujsiev5mqjq","title":"CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally","title_en":null,"outlets":2,"brief":null,"page":"https://hottub.news/stories/cisa-says-attackers-are-exploiting-two-critical-citrix-netscaler-flaws-2wujuu3lbu","count":2,"items":[{"id":"n_o2z2xa6rflakvialuzma","seq":591799,"kind":"article","title":"美國CISA警告Citrix NetScaler重大漏洞遭積極利用","title_en":"US CISA warns of active exploitation of major Citrix NetScaler vulnerability","url":"https://www.ithome.com.tw/news/179258","summary":"新聞 9月27日美國網路安全與基礎設施安全局（CISA）提出警告， 他們已掌握兩個Citrix NetScaler重大漏洞遭積極利用的證據 ，將其加入已遭利用的漏洞名單（KEV），並要求聯邦機構必須在9月30日前完成修補。這些漏洞是：輸入驗證不當漏洞CVE-2026-88771，以及記憶體緩衝區操作限制不當漏洞CVE-2026-88772。 上述漏洞的CVSS v4.0嚴重程度評分皆達到9.5分，相當危險，攻擊者可在不需取得授權的情況下，利用 CVE-2026-88771 執行任意程式碼；另一個弱點 CVE-2026-88772 ，攻擊者不僅能用於遠端程式碼執行（RCE）攻擊，也可能造成阻斷服務（DoS）的現象。","published":"2026-09-29T04:57:24Z","seen":"2026-09-29T06:09:59Z","lang":"zh","country":"TW","source":{"id":"kite-ithome-com-tw-c23d09","name":"ithome.com.tw","domain":"ithome.com.tw","outlet":{"wikidata":"Q123398745","name":"iThome","type":"magazine","country":"TW","designations":["magazine","news website"]}},"via":"kite-ithome-com-tw-c23d09","authors":["周峻佑"],"entities":[{"id":"Q5205058","name":"Cybersecurity and Infrastructure Security Agency","type":"org"}],"story":"st_2wujuu3lbujsiev5mqjq","category":"science-technology","category_p":0.6700000166893005,"sentiment":"negative","tone":-0.6899999976158142,"political":0.2800000011920929},{"id":"n_2wujuu3lbujsiev5mqjq","seq":398333,"kind":"article","title":"CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally","url":"https://thehackernews.com/2026/09/cisa-says-attackers-are-exploiting-two.html","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to","published":"2026-09-28T07:21:49Z","seen":"2026-09-28T10:18:21Z","lang":"en","source":{"id":"kite-thehackernews-com-16b1d7","name":"thehackernews.com","domain":"thehackernews.com"},"via":"kite-thehackernews-com-16b1d7","topics":["cybersecurity"],"authors":["author"],"image":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG1pBfETB-EOlAvKfZwROp5B3Nr3d00xBbxRPhsq5hDBvK8QTVYmc2r8tR8RNz7omvXWoufetWbVk1S-tZ74b-z0nxsHS_Zz7XnN4Vs7VGvDtlnOhsfG0ecx-LX_kuRwBLJwkIMN-26auGXjzdcAS2Yz8sdQ2U_kDtKpQOnOYD18r6WEu1twQ79p_ZJGhD/s1600/ct.jpg","mentions":3,"story":"st_2wujuu3lbujsiev5mqjq","category":"science-technology","category_p":0.7400000095367432,"sentiment":"negative","tone":-0.7099999785423279,"political":0.17000000178813934}]}