跳到主内容
@wquguru
精选75Cloudflare WAF(Changelog)云与平台

Cloudflare WAF 新增规则拦截 Citrix 与 Kemp 漏洞利用

WAF - WAF Release - 2026-07-14

原文
发到 X
推荐理由

Cloudflare WAF 用户需关注:新规则默认拦截两个高危漏洞利用,建议确认规则已生效,并检查现有配置是否冲突。

This release introduces new rules targeting critical infrastructure vulnerabilities. These include an unauthenticated memory disclosure flaw in Citrix NetScaler ADC and Gateway (CVE-2026-8451) and a high-severity pre-authentication remote code execution (RCE) vulnerability in Progress Kemp LoadMaster (CVE-2026-8037).

Key Findings

  • CVE-2026-8451: An insufficient input validation vulnerability affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Identity Provider (IdP). Remote, unauthenticated attackers can exploit this flaw by sending malformed requests to trigger a memory overread, allowing them to leak chunks of sensitive data from adjacent appliance memory.
  • CVE-2026-8037: A critical OS command injection vulnerability in Progress Kemp LoadMaster load balancers allows unauthenticated remote attackers to achieve remote code execution (RCE).
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...76973ac4N/ACitrix Netscaler ADC - Insufficient Input Validation - CVE:CVE-2026-8451LogBlockThis is a new detection.
Cloudflare Managed Ruleset...10233f36N/AProgress Kemp LoadMaster - Remote Code Execution - CVE:CVE-2026-8037LogBlockThis is a new detection.

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近