CISA KEV速報 — 2026-09-27に2件追加
CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-27付けで2件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。
CVE-2026-88771 — Citrix NetScaler
脆弱性名: CVE-2026-88771
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | Citrix / NetScaler |
| 対応期限(CISA) | 2026-09-30 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-88771 |
CVE-2026-88772 — Citrix NetScaler
脆弱性名: CVE-2026-88772
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | Citrix / NetScaler |
| 対応期限(CISA) | 2026-09-30 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-88772 |
※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。