Citrix NetScaler 제로데이 3건 잇달아 악용
미·호주도 새 취약점을 경고했지만, Citrix는 앞선 취약점들과 별개라고 밝혔다.
독립 출처 6곳 · 기사 136건을 바탕으로 정리했습니다.
Today Score 61.5 / 100선정 근거 ↓TODAY SCORE
61.5/ 100
1위보다 10.6점 낮음
보도 신호를 합산한 점수입니다. 사실의 정확도나 요약의 신뢰도를 뜻하지 않습니다.
집계
30초 요약
Citrix NetScaler에서 악용 중인 제로데이 취약점이 한 주도 안 돼 세 건 보고됐다. Citrix는 앞서 긴급 패치를 냈으며, 당국은 추가 취약점에도 경고를 발표했다.
기사 제목과 RSS 요약문을 바탕으로 AI가 정리했습니다. 세부 내용은 원문에서 확인하세요. · 작성
WHAT · 무슨 일이 있었나
9월 말 미국·영국 당국이 NetScaler 취약점 악용을 경고했다. Citrix는 10월 4일 CVE-2026-88779 긴급 업데이트를 공개했고, 이후 보도들은 앞서 패치된 취약점들과 별도로 새 문제가 확인됐다고 전했다. Citrix는 새 문제가 지난주 보고된 취약점들과 관련 없다고 밝혔지만, 10월 6일 보도는 한 주도 안 돼 세 번째 악용 제로데이가 공개됐다고 전했다.
WHY · 왜 중요한가
NetScaler 관리자는 각 취약점이 자사 장비에 영향을 주는지 확인하고, 해당되는 업데이트나 완화 조치를 적용해야 한다.
NEXT · 다음에 확인할 것
기사에 근거해 AI가 정리한 확인 항목입니다. 미래 결과를 예측하거나 확정한 내용은 아닙니다.
세 번째 취약점의 영향 범위와 Citrix의 업데이트·완화 안내가 구체화되는지 확인할 필요가 있다.
근거와 원문 확인
“Citrix discloses third actively exploited NetScaler zero-day in less than a week”
Citrix discloses third actively exploited NetScaler zero-day in less than a week ↗
타임라인
미국·영국 등이 악용 중인 NetScaler 취약점을 경고했다.
US, UK warn of exploited Citrix NetScaler zero-day bugsCitrix가 악용된 CVE-2026-88779에 대한 긴급 업데이트를 공개했다.
Citrix patches NetScaler SAML zero-day exploited in attacks보도에 따르면 Citrix는 새로 관찰된 문제가 지난주 취약점들과 무관하다고 밝혔다.
US, Australia warn of latest Citrix vulnerability after NetScaler advisory보도가 한 주도 안 돼 세 번째 악용 NetScaler 제로데이가 공개됐다고 전했다.
Citrix discloses third actively exploited NetScaler zero-day in less than a week
원문 출처 · 6곳
재전송을 포함한 기사 136건입니다. 원문은 새 탭에서 열립니다.
- The Hacker NewsCritical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
- Hacker NewsSecurity researcher claims they found KVM guest-host escape flaw
- The Hacker NewsClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
- Hacker NewsCitrix discloses third actively exploited NetScaler zero-day in less than a week
- BleepingComputerRejetto HFS servers now actively scanned for critical RCE flaw
- The RecordUS, Australia warn of latest Citrix vulnerability after NetScaler advisory
- The Hacker NewsMicrosoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
- BleepingComputerNew Dell System Update flaw lets hackers gain root privileges
- The Hacker News⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
- SecurityWeekLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
- The Hacker NewsRealtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
- Hacker NewsKVM Escape Zero-Day
- SecurityWeekExploitation Hits Rejetto HFS Vulnerability Discovered by AI
- The Hacker NewsAttackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
- The Hacker NewsNew NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- SecurityWeekExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
- BleepingComputerCitrix patches NetScaler SAML zero-day exploited in attacks
- Hacker NewsXray-core concealed a certificate verification bypass vulnerability
- Hacker NewsGuillermo Rauch: "We've confirmed a KVM 0day through our Vercel bounty program"
- Hacker NewsKVM 0day
- The Hacker NewsWarlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- Hacker NewsHow recurring network maintenance exposed 6 bugs
- SecurityWeekFortra Patches Critical Vulnerabilities in BoKS
- The Hacker NewsGitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
- The Hacker NewsDell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
- BleepingComputerGitLab warns of critical RCE vulnerability in AI Gateway service
- Hacker NewsFortinet sounds the alarm over actively exploited FortiMail zero-day
- The Record'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
- BleepingComputerThe EDR blind spot: 3 ways browser attacks evade endpoint telemetry
- SecurityWeekmacOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
- Hacker NewsFTP Backdoor Exploitation: From NMAP Reconnaissance to Root Access
- BleepingComputerDell asks admins to patch max severity CSM flaws as soon as possible
- Hacker NewsZammad zero-days for RCE and root (CVE-2026-102489/102490)
- SecurityWeekWarlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
- SecurityWeekExploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- The Hacker NewsCritical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- Hacker NewsMass exploitation of Citrix NetScaler: What we currently know
- Hacker NewsSeveral vulnerabilities have been discovered in the Linux kernel
- BleepingComputerFortinet warns of critical FortiMail flaw exploited in zero-day attacks
- Hacker NewsFrom Select to Sysadmin: Hijacking Microsoft SQL Copilot (CVE-2026-65669)
- BleepingComputerKiteworks patches max severity code injection vulnerability
- SecurityWeekZimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
- SecurityWeekZammad Zero-Days Exploited in AI-Powered DIVD Hack
- The Hacker NewsCISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- Hacker NewsTanStack Start critical XSS in server functions (CVE-2026-102989)
- Hacker NewsWe found a Claris FileMaker authorization bypass (CVE-2026-86934)
- SecurityWeekCisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
- The Hacker NewsApple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- The Hacker NewsCitrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
- Hacker NewsCVE-2026-86950: An in-the-wild iOS bug with a possible WhatsApp zero-click path
- Hacker News16-year-old found Microsoft bug, got admin access to 17.3T-row databases
- Ars TechnicaAttackers have been exploiting critical Zimbra flaw to steal emails
- BleepingComputerDIVD says Zammad zero-days enabled AI-driven network breach
- Hacker NewsThe Exploit Bulletin – a free daily brief of exploited vulns to act on today
- The Hacker NewsAttackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
- BleepingComputerCISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
- The Hacker NewsCisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- BleepingComputerCisco warns of new SD-WAN zero-day exploited in attacks
- SecurityWeekWatchGuard Patches Critical Fireware OS Code Injection Vulnerability
- SecurityWeekGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
- BleepingComputerTeamViewer urges users to patch severe flaws “as soon as possible”
- SecurityWeekChrome, Firefox Updates Patch Over 100 Vulnerabilities
- The Hacker NewsKnow Your Enemy: Browser-Based Attack Techniques in 2026
- The Hacker NewsAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
- SecurityWeekHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
- The Hacker NewsCitrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
- Hacker NewsCustom malware used in Citrix 0-day attacks targeting govt, banks, professional
- BleepingComputerHackers exploit Citrix NetScaler zero-day to deploy web shells
- Hacker NewsApple patches CoreGraphics zero-day already exploited in targeted attacks
- BleepingComputerNew Spectre v2 attack variant leaks Linux root password hash in minutes
- The Hacker NewsNew Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
- SecurityWeekNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
- The Hacker NewsKiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
- TechCrunchStill running iOS 26? Update your iPhones, iPads, and Macs for this urgent security fix
- Hacker NewsKestra Unauthenticated Remote Code Execution CVE-2026-49869
- Hacker NewsMCP Python SDK OAuth flaw enabled account takeover
- BleepingComputerKiteworks patches critical flaw, brings customer systems online
- BleepingComputerApple patches CoreGraphics zero-day flaw exploited in attacks
- Hacker NewsCVE-2026-85706 (CVSS 10.0)
- SecurityWeekApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
- The Hacker NewsOfficial MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
- Hacker NewsTaking 'execute logging' a bit too literally CVE-2026-88771
- The Hacker NewsApple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- Hacker NewsElastic Agentic SOC Vulnerable to Credential Theft
- Hacker NewsActive, in-the-wild exploitation of CVE-2026-88771 with IoCs
- The RecordUS, UK warn of exploited Citrix NetScaler zero-day bugs
- Hacker NewsCitrix NetScaler PreAuth Command Injection CVE-2026-88771
- Hacker NewsOne resident login, an entire apartment complex: CVE-2026-75960
- SecurityWeekKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
- Hacker NewsI found an SSRF in Google's official MCP Toolbox (CVE-2026-14540)
- SecurityWeekCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
- The Hacker NewsCISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
- BleepingComputerCISA orders feds to patch exploited Citrix flaws by Wednesday
- Hacker NewsCitrix NetScaler Remote Code Execution
- BleepingComputerCitrix confirms two NetScaler RCE zero-days exploited in attacks
- SecurityWeekMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
- The Hacker NewsWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Hacker NewsSix Bazel patches from an AI software factory, plus a remote-cache security bug
- The Hacker NewsAttackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- The Hacker NewsSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- BleepingComputerCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
- Hacker NewsSomeone's attacking a critical 0-day RCE in F5 BIG-IP APM
- Hacker NewsImminent Zero-Day Attack: KiteWorks Urges Customers to Shut Down Servers
- Hacker NewsThe "FREAK" TLS/SSL flaw, and related thoughts
- SecurityWeek‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
- Hacker NewsCVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
- The Hacker NewsWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
- Hacker NewsVulnerability Cve-2026-82958
- Hacker NewsDecades-old file security flaws found in Android, Linux, macOS, and Windows
- Hacker NewsCISA active Linux kernel CVEs (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
- BleepingComputerHackers now exploit critical Roundcube flaw in code injection attacks
- BleepingComputerCISA: Ransomware gangs now exploiting critical TeamCity flaw
- SecurityWeekSolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
- Hacker NewsHackers Actively Exploit Check Point VPN Flaw
- BleepingComputerCheck Point warns of hackers exploiting Security Gateway VPN RCE flaw
- The Hacker NewsMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
- BleepingComputerInfraTrust report warns network management systems under attack
- Hacker NewsLatest BGP hijack targets hosting software vendor
- BleepingComputerArista patches actively exploited VeloCloud Orchestrator zero-day
- SecurityWeekAdobe Patches Critical Flaws in Connect, AEM Forms
- SecurityWeekArista Urges Immediate Patching of Exploited VCO Zero-Day
- The Hacker NewsF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- The Hacker NewsChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- SecurityWeekCritical F5 BIG-IP Vulnerability Exploited as Zero-Day
- BleepingComputerF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
- SecurityWeekCheck Point Patches Exploited Management Server Zero-Day
- BleepingComputerChinese hackers exploit WordPress, Zyxel flaws to steal govt data
- The Hacker NewsCheck Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
- The Hacker NewsCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
- BleepingComputerCheck Point warns of Management Server zero-day exploited in attacks
- BleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routers
- The Hacker NewsNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
- SecurityWeekRecent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
- BleepingComputerCISA orders feds to patch Zyxel flaw exploited for data theft
- The Hacker NewsZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
- BleepingComputerCISA alerts of active exploitation of three Linux kernel flaws