

{"id":50114,"date":"2026-09-27T23:38:58","date_gmt":"2026-09-28T04:38:58","guid":{"rendered":"https:\/\/rud.is\/b\/?p=50114"},"modified":"2026-09-27T23:38:58","modified_gmt":"2026-09-28T04:38:58","slug":"50065-3","status":"publish","type":"post","link":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/","title":{"rendered":"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778"},"content":{"rendered":"<style>\nh2 {\n  margin-top: 1em;\n}\ntd {\n  padding-left: 6px;\n  padding-right: 6px;\n}\n<\/style>\n<p>Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix.<\/p>\n<p>It&#8217;s also has this gem in the header:<\/p>\n<pre><code class=\"language-html\">&lt;meta name=\"robots\" content=\"noindex\"&gt;\n<\/code><\/pre>\n<p>Source: <a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778\/\">NetScaler ADC and NetScaler Gateway security bulletin<\/a><\/p>\n<p>Let&#8217;s make sure it gets indexed in other ways!<\/p>\n<p>Here&#8217;s some helpful info you&#8217;ll find more details of in their bulletin.<\/p>\n<h2>Critical CVEs<\/h2>\n<p>CVE-2026-88771 is a remote code execution flaw from improper input validation. An unauthenticated attacker can run arbitrary commands. Every deployment is affected, and no optional feature is required.<\/p>\n<p>CVE-2026-88772 is a memory overflow that leads to remote code execution or denial of service. The precondition is DTLS. DTLS is enabled by default on VPN virtual servers, so a deployment that never turned it off is exposed.<\/p>\n<p>CVE-2026-88773 scores 9.3. It is an HTTP request smuggling flaw that affects deployments with HTTP or SSL virtual servers.<\/p>\n<h2>All eight vulnerabilities<\/h2>\n<table>\n<thead>\n<tr>\n<th>CVE<\/th>\n<th>Description<\/th>\n<th>Precondition<\/th>\n<th>CWE<\/th>\n<th>CVSS v4.0<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2026-88771<\/td>\n<td>Remote code execution from improper input validation.<\/td>\n<td>All deployments, default config included.<\/td>\n<td>CWE-20<\/td>\n<td>9.5<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88772<\/td>\n<td>Memory overflow that leads to remote code execution or denial of service.<\/td>\n<td>DTLS enabled. Default on VPN virtual servers.<\/td>\n<td>CWE-119<\/td>\n<td>9.5<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88773<\/td>\n<td>HTTP request smuggling.<\/td>\n<td>HTTP or SSL virtual servers.<\/td>\n<td>CWE-444<\/td>\n<td>9.3<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88774<\/td>\n<td>Policy bypass from improper HTTP URL expression use.<\/td>\n<td>HTTP or SSL virtual servers.<\/td>\n<td>CWE-16<\/td>\n<td>7.0<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88775<\/td>\n<td>Memory overflow that leads to erroneous behavior or denial of service.<\/td>\n<td>Gateway or AAA virtual server.<\/td>\n<td>CWE-119<\/td>\n<td>8.8<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88776<\/td>\n<td>Memory overflow that leads to erroneous behavior or denial of service.<\/td>\n<td>Oracle load balancing virtual server.<\/td>\n<td>CWE-119<\/td>\n<td>8.8<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88777<\/td>\n<td>Memory overflow that leads to erroneous behavior or denial of service.<\/td>\n<td>LB\/CS or CGNAT-LSN\/NAT64 with a non-HTTP L7 protocol.<\/td>\n<td>CWE-119<\/td>\n<td>8.8<\/td>\n<\/tr>\n<tr>\n<td>CVE-2026-88778<\/td>\n<td>TCP initial sequence number prediction.<\/td>\n<td>TCP enabled.<\/td>\n<td>CWE-342<\/td>\n<td>8.8<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Check your exposure<\/h2>\n<p>Run the checks that match your deployment.<\/p>\n<ul>\n<li>CVE-2026-88771: every deployment is exposed. No check is needed.<\/li>\n<li>CVE-2026-88772: DTLS is on. <code>add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE<\/code> means on. <code>-dtls OFF<\/code> means off. A <code>DTLS<\/code> virtual server means on.<\/li>\n<li>CVE-2026-88773 and CVE-2026-88774: you use an LB, CS, VPN, or Authentication virtual server of type HTTP or SSL.<\/li>\n<li>CVE-2026-88775: the config holds <code>add vpn vserver .*<\/code> or <code>add authentication vserver .*<\/code>.<\/li>\n<li>CVE-2026-88776: the config holds <code>add lb vserver.*ORACLE.*<\/code>.<\/li>\n<li>CVE-2026-88777: you run LB\/CS or CGNAT-LSN\/NAT64 with FTP, RTSP, DNS64, or NAT64 enabled.<\/li>\n<li>CVE-2026-88778: a listed virtual server type is present, and <code>show ns tcpparam | grep \"Enhanced ISN Generation\"<\/code> returns <code>DISABLED<\/code>.<\/li>\n<\/ul>\n<h2>Fix it<\/h2>\n<ol>\n<li>Install a fixed release: 14.1-73.37, 13.1-64.23, 14.1-FIPS 14.1-73.37, or 13.1-FIPS and 13.1-NDcPP 13.1.37.279.<\/li>\n<li>Take the later release in the branch when one exists.<\/li>\n<li>Run <code>show ns variable<\/code>. If it returns output, install 13.1-64.24, not 13.1-64.23.<\/li>\n<li>Make sure your identity provider signs SAML assertions.<\/li>\n<li>Turn on the telemetry channel and run the IoC scan from the NetScaler Console Security Advisory page.<\/li>\n<li>Forward NetScaler logs to your SIEM platform.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix. It&#8217;s also has this gem in the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":0,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"federated","footnotes":"","jetpack_post_was_ever_published":false},"categories":[681],"tags":[],"class_list":["post-50114","post","type-post","status-publish","format-standard","hentry","category-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778 - rud.is<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778 - rud.is\" \/>\n<meta property=\"og:description\" content=\"Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix. It&#8217;s also has this gem in the [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/\" \/>\n<meta property=\"og:site_name\" content=\"rud.is\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-28T04:38:58+00:00\" \/>\n<meta name=\"author\" content=\"hrbrmstr\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"hrbrmstr\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/\"},\"author\":{\"name\":\"hrbrmstr\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"headline\":\"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778\",\"datePublished\":\"2026-09-28T04:38:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/\"},\"wordCount\":490,\"publisher\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/\",\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/\",\"name\":\"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778 - rud.is\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#website\"},\"datePublished\":\"2026-09-28T04:38:58+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/2026\\\/09\\\/27\\\/50065-3\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/rud.is\\\/b\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#website\",\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/\",\"name\":\"rud.is\",\"description\":\"&quot;In God we trust. All others must bring data&quot;\",\"publisher\":{\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/rud.is\\\/b\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/rud.is\\\/b\\\/#\\\/schema\\\/person\\\/d7cb7487ab0527447f7fda5c423ff886\",\"name\":\"hrbrmstr\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\",\"width\":460,\"height\":460,\"caption\":\"hrbrmstr\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/rud.is\\\/b\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/ukr-shield.png?fit=460%2C460&ssl=1\"},\"description\":\"Don't look at me\u2026I do what he does \u2014 just slower. #rstats avuncular \u2022 ?Resistance Fighter \u2022 Cook \u2022 Christian \u2022 [Master] Chef des Donn\u00e9es de S\u00e9curit\u00e9 @ @rapid7\",\"sameAs\":[\"http:\\\/\\\/rud.is\"],\"url\":\"https:\\\/\\\/rud.is\\\/b\\\/author\\\/hrbrmstr\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778 - rud.is","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/","og_locale":"en_US","og_type":"article","og_title":"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778 - rud.is","og_description":"Citrix published a security bulletin on September 27, 2026. It covers eight vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. Two of them, CVE-2026-88771 and CVE-2026-88772, are under active exploitation. Both score 9.5 under CVSS v4.0. This post summarizes the critical CVEs, the exposure checks, and the fix. It&#8217;s also has this gem in the [&hellip;]","og_url":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/","og_site_name":"rud.is","article_published_time":"2026-09-28T04:38:58+00:00","author":"hrbrmstr","twitter_card":"summary_large_image","twitter_misc":{"Written by":"hrbrmstr","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/#article","isPartOf":{"@id":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/"},"author":{"name":"hrbrmstr","@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"headline":"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778","datePublished":"2026-09-28T04:38:58+00:00","mainEntityOfPage":{"@id":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/"},"wordCount":490,"publisher":{"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"articleSection":["Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/","url":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/","name":"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778 - rud.is","isPartOf":{"@id":"https:\/\/rud.is\/b\/#website"},"datePublished":"2026-09-28T04:38:58+00:00","breadcrumb":{"@id":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/rud.is\/b\/2026\/09\/27\/50065-3\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/rud.is\/b\/"},{"@type":"ListItem","position":2,"name":"Citrix NetScaler ADC and Gateway bulletin: CVE-2026-88771 through CVE-2026-88778"}]},{"@type":"WebSite","@id":"https:\/\/rud.is\/b\/#website","url":"https:\/\/rud.is\/b\/","name":"rud.is","description":"&quot;In God we trust. All others must bring data&quot;","publisher":{"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/rud.is\/b\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/rud.is\/b\/#\/schema\/person\/d7cb7487ab0527447f7fda5c423ff886","name":"hrbrmstr","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","url":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","contentUrl":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1","width":460,"height":460,"caption":"hrbrmstr"},"logo":{"@id":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2023\/10\/ukr-shield.png?fit=460%2C460&ssl=1"},"description":"Don't look at me\u2026I do what he does \u2014 just slower. #rstats avuncular \u2022 ?Resistance Fighter \u2022 Cook \u2022 Christian \u2022 [Master] Chef des Donn\u00e9es de S\u00e9curit\u00e9 @ @rapid7","sameAs":["http:\/\/rud.is"],"url":"https:\/\/rud.is\/b\/author\/hrbrmstr\/"}]}},"jetpack_shortlink":"https:\/\/wp.me\/p23idr-d2i","jetpack_likes_enabled":true,"jetpack-related-posts":[{"id":48030,"url":"https:\/\/rud.is\/b\/2026\/05\/14\/three-cves-and-the-may-2026-exploit-chain-nobodys-taking-seriously\/","url_meta":{"origin":50114,"position":0},"title":"Three CVEs and the May 2026 Exploit Chain Nobody&#8217;s Taking Seriously","author":"hrbrmstr","date":"2026-05-14","format":false,"excerpt":"May 2026 dropped three critical Linux vulnerabilities on a near-weekly cadence, and the security discourse has mostly treated them as three separate bad days. They're not. Together they form a reliable, race-free, forensically quiet kill chain from the public internet to root, and if you're running nginx in front of\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/rud.is\/b\/category\/cybersecurity\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":23595,"url":"https:\/\/rud.is\/b\/2024\/12\/04\/cvesky-monitoring-the-bluesky-jetstream-for-cve-mentions\/","url_meta":{"origin":50114,"position":1},"title":"CVESky: Monitoring The Bluesky Jetstream For CVE Mentions","author":"hrbrmstr","date":"2024-12-04","format":false,"excerpt":"I mentioned this new app over at the newsletter but it deserves a mention on the legacy blog. CVESky is a tool to explore CVE chatter on Bluesky. At work, we're ingesting the Bluesky Jetstream and watching for CVE chatter, excluding daft bots that just regurgitate new NVD CVEs. There\u2026","rel":"","context":"In &quot;bluesky&quot;","block_context":{"text":"bluesky","link":"https:\/\/rud.is\/b\/category\/bluesky\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2024\/12\/og-image.png?fit=1200%2C631&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2024\/12\/og-image.png?fit=1200%2C631&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2024\/12\/og-image.png?fit=1200%2C631&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2024\/12\/og-image.png?fit=1200%2C631&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2024\/12\/og-image.png?fit=1200%2C631&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":1865,"url":"https:\/\/rud.is\/b\/2012\/12\/28\/cve-queries-right-from-your-browsers-address-bar\/","url_meta":{"origin":50114,"position":2},"title":"CVE Queries Right From Your Browser&#8217;s Address Bar","author":"hrbrmstr","date":"2012-12-28","format":false,"excerpt":"I'm not sure why I never did this earlier, but a post on LifeHacker gave me an idea to add location bar quick search of CVEs (Common Vulnerabilities and Exposures), no doubt due to their example on searching LifeHacker for \"security\". My two favorite sites for searching CVE specifics are,\u2026","rel":"","context":"In &quot;Browsers&quot;","block_context":{"text":"Browsers","link":"https:\/\/rud.is\/b\/category\/browsers\/"},"img":{"alt_text":"Screenshot_12_28_12_8_58_PM","src":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2012\/12\/Screenshot_12_28_12_8_58_PM.png?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":24853,"url":"https:\/\/rud.is\/b\/2025\/04\/16\/american-cyber-sigh\/","url_meta":{"origin":50114,"position":3},"title":"American [Cyber] Sigh","author":"hrbrmstr","date":"2025-04-16","format":false,"excerpt":"A long, long time ago I can still remember How those CVEs would make me smile And I knew if I had my chance To patch a vuln or take a stance Maybe we\u2019d be secure for a while But April ides made me shiver With each leaked memo and\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/rud.is\/b\/category\/cybersecurity\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":49107,"url":"https:\/\/rud.is\/b\/2026\/07\/02\/unjamming-the-chrome-releases-blog\/","url_meta":{"origin":50114,"position":4},"title":"Unjamming the Chrome Releases Blog","author":"hrbrmstr","date":"2026-07-02","format":false,"excerpt":"For the second time in a row, a post by cr0w on Mastodon regarding the Chrome release blog appearing to not render anything resulted in me firing up lynx to show a sub-second load and render, then finally doing something a bit more tangible about the situation. The 81-Second Wall\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/rud.is\/b\/category\/cybersecurity\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2026\/07\/how-to-unjam-a-paper-shredder.jpg?fit=800%2C550&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2026\/07\/how-to-unjam-a-paper-shredder.jpg?fit=800%2C550&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2026\/07\/how-to-unjam-a-paper-shredder.jpg?fit=800%2C550&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/rud.is\/b\/wp-content\/uploads\/2026\/07\/how-to-unjam-a-paper-shredder.jpg?fit=800%2C550&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":18584,"url":"https:\/\/rud.is\/b\/2024\/03\/23\/vulnchecks-free-community-kev-cve-apis-code-golang-cli-utility\/","url_meta":{"origin":50114,"position":5},"title":"VulnCheck&#8217;s Free Community KEV &#038; CVE APIs  (Code &#038; Golang CLI Utility)","author":"hrbrmstr","date":"2024-03-23","format":false,"excerpt":"VulnCheck has some new, free API endpoints for the cybersecurity community. Two extremely useful ones are for their extended version of CISA\u2019s KEV, and an in-situ replacement for NVD\u2019s sad excuse for an API and soon-to-be-removed JSON feeds. There are two ways to work with these APIs. One is retrieve\u2026","rel":"","context":"In &quot;APIs&quot;","block_context":{"text":"APIs","link":"https:\/\/rud.is\/b\/category\/apis\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/50114","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/comments?post=50114"}],"version-history":[{"count":3,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/50114\/revisions"}],"predecessor-version":[{"id":50117,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/posts\/50114\/revisions\/50117"}],"wp:attachment":[{"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/media?parent=50114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/categories?post=50114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rud.is\/b\/wp-json\/wp\/v2\/tags?post=50114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}