B
今週中
Citrix NetScaler ADCおよびNetScaler Gatewayの脆弱性(CVE-2026-88772、CVE-2026-88771)を悪用し…
📌 一言でいうと
Citrix NetScaler ADCおよびNetScaler Gatewayの脆弱性(CVE-2026-88772、CVE-2026-88771)を悪用し、ルート権限を取得する攻撃が確認されました。攻撃者は認証をバイパスしてNetScaler Packet Processing Engineを停止させ、初期アクセスを確立します。その後、WHIPSHOTやSLAPSHOTなどのポストエクスプロイトツールキットを配備し、北米や欧州の政府、金融、技術、教育などの組織を標的にしています。
🔍該当判定
- Citrix NetScaler ADC を利用している
- Citrix NetScaler Gateway を利用している
- 社外から社内ネットワークへ接続するためのVPN装置として NetScaler を導入している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
最新のセキュリティパッチを適用し、NetScaler ADCおよびNetScaler Gatewayを最新バージョンに更新してください。また、不審なプロセスの実行や認証バイパスの兆候がないかログを確認してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Citrix NetScaler CVE-2026-88772/88771 対応について
お疲れさまです。NetScalerの脆弱性を悪用したルート権限奪取の攻撃に関する情報共有です。
■ 概要
Citrix NetScaler ADCおよびGatewayにおいて、認証バイパスおよびルート権限取得が可能な脆弱性が悪用されています。攻撃者はCVE-2026-88772を用いて認証を回避し、ルート権限を確立した後、WHIPSHOTやSLAPSHOTなどのツールキットを配備します。
■ 影響範囲
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
■ 対応手順
1. ベンダーから提供されている最新のセキュリティパッチを適用し、製品を最新バージョンに更新してください。
2. NetScaler Packet Processing Engine (NSPPE) の予期せぬ停止や、不審なPHPウェブシェルの配置がないかログを確認してください。
■ 参考情報
- Citrix 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 至急
お疲れさまです。NetScalerの脆弱性を悪用したルート権限奪取の攻撃に関する情報共有です。
■ 概要
Citrix NetScaler ADCおよびGatewayにおいて、認証バイパスおよびルート権限取得が可能な脆弱性が悪用されています。攻撃者はCVE-2026-88772を用いて認証を回避し、ルート権限を確立した後、WHIPSHOTやSLAPSHOTなどのツールキットを配備します。
■ 影響範囲
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
■ 対応手順
1. ベンダーから提供されている最新のセキュリティパッチを適用し、製品を最新バージョンに更新してください。
2. NetScaler Packet Processing Engine (NSPPE) の予期せぬ停止や、不審なPHPウェブシェルの配置がないかログを確認してください。
■ 参考情報
- Citrix 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 至急
Subject: [Urgent] Action Required: Citrix NetScaler CVE-2026-88772/88771
Dear IT/Security Team,
We are sharing critical information regarding the exploitation of vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway.
■ Overview
Threat actors are exploiting CVE-2026-88772 and CVE-2026-88771 to bypass authentication and gain root-level access. Once access is established, attackers are deploying post-exploitation toolkits such as WHIPSHOT and SLAPSHOT.
■ Affected Products
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
■ Required Actions
1. Immediately apply the latest security patches provided by Citrix to update your appliances to the latest version.
2. Review system logs for unexpected terminations of the NetScaler Packet Processing Engine (NSPPE) or the presence of unauthorized PHP web shells.
■ Reference
- Citrix Official Security Advisory
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing critical information regarding the exploitation of vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway.
■ Overview
Threat actors are exploiting CVE-2026-88772 and CVE-2026-88771 to bypass authentication and gain root-level access. Once access is established, attackers are deploying post-exploitation toolkits such as WHIPSHOT and SLAPSHOT.
■ Affected Products
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
■ Required Actions
1. Immediately apply the latest security patches provided by Citrix to update your appliances to the latest version.
2. Review system logs for unexpected terminations of the NetScaler Packet Processing Engine (NSPPE) or the presence of unauthorized PHP web shells.
■ Reference
- Citrix Official Security Advisory
Priority: High
Deadline: Immediate