【資安漏洞預警】NetScaler ADC與NetScaler Gateway存在多項高風險安全漏洞,請儘速確認並進行修補
【Security Vulnerability Alert】NetScaler ADC and NetScaler Gateway have multiple high-risk security vulnerabilities, please confirm and apply patches as soon as possible

發布單位:圖資處數位服務組
日期範圍:2026/7/21 ~ 2027/1/21
 
發布單位:圖資處數位服務組
日期範圍:2026/7/21 ~ 2027/1/21
行政 行政公告
全體

轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202607-00000004

[內容說明]
研究人員發現NetScaler ADC與NetScaler Gateway存在多項高風險安全漏洞(CVE-2026-8451、CVE-2026-8452、CVE-2026-8655、CVE-2026-10816、CVE-2026-10817及CVE-2026-13474),其中最嚴重之CVE-2026-8452為記憶體溢位(Memory Overflow)漏洞,當受影響裝 置被設定為Gateway或AAA Virtual Server功能時,未經身分鑑別之遠端攻擊者可利用此漏洞造成系統異常、阻斷服務或其他非預期行為,請儘速確認並進行修補。

[影響平台]
NetScaler ADC與NetScaler Gateway 14.1至14.1-72.61(不含)版本
NetScaler ADC與NetScaler Gateway 13.1至13.1-63.18(不含)版本
NetScaler ADC FIPS 14.1-72.61(不含)以前版本
NetScaler ADC FIPS與NDcPP 13.1-37.272(不含)以前版本

[建議措施]
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-8451
2. https://nvd.nist.gov/vuln/detail/CVE-2026-8452
3. https://nvd.nist.gov/vuln/detail/CVE-2026-8655
4. https://nvd.nist.gov/vuln/detail/CVE-2026-10816
5. https://nvd.nist.gov/vuln/detail/CVE-2026-10817
6. https://nvd.nist.gov/vuln/detail/CVE-2026-13474
7. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Forwarded National Information Security Analysis and Sharing Center Security Advisory Alert NISAC-200-202607-00000004

[Description]
Researchers have discovered multiple high-risk security vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-8451、CVE-2026-8452、CVE-2026-8655、CVE-2026-10816、CVE-2026-10817及CVE-2026-13474). Among them, the most severe CVE-2026-8452 is a memory overflow vulnerability (Memory Overflow). When the affected devices are configured as Gateway or AAA Virtual Server functions, unauthenticated remote attackers can exploit this vulnerability to cause system anomalies, denial of service, or other unexpected behaviors. Please confirm and apply patches as soon as possible.

[Affected Platform]
NetScaler ADC and NetScaler Gateway versions 14.1 to 14.1-72.61 (not including)
NetScaler ADC and NetScaler Gateway versions 13.1 to 13.1-63.18 (not including)
NetScaler ADC FIPS versions prior to 14.1-72.61 (not including)
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.272 (not including)

[Recommendations]
The official has released fixes for the vulnerabilities. Please refer to the official instructions for updates at the following URL: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-8451
2. https://nvd.nist.gov/vuln/detail/CVE-2026-8452
3. https://nvd.nist.gov/vuln/detail/CVE-2026-8655
4. https://nvd.nist.gov/vuln/detail/CVE-2026-10816
5. https://nvd.nist.gov/vuln/detail/CVE-2026-10817
6. https://nvd.nist.gov/vuln/detail/CVE-2026-13474
7. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
Top↑