JPCERT/CC Issues Multiple Critical Security Alerts for Adobe Acrobat, Citrix NetScaler, and F5 BIG-IP Vulnerabilities

Japan’s Computer Emergency Response Team Coordination Center (JPCERT/CC) has issued a series of urgent security advisories warning organizations across Japan and the Asia-Pacific region of critical vulnerabilities affecting widely used enterprise software.

Among the most pressing alerts are multiple vulnerabilities in Adobe Acrobat and Reader, identified under security bulletins APSB26-44, APSB26-43, and APSB26-26. These flaws could potentially allow attackers to execute arbitrary code or compromise systems when users open maliciously crafted PDF documents — a common attack vector in phishing campaigns targeting Japanese businesses.

Additionally, JPCERT/CC has flagged a serious out-of-bounds read vulnerability (CVE-2026-3055) affecting Citrix NetScaler ADC and NetScaler Gateway, both of which are widely deployed in corporate network environments throughout the region. Exploitation of this flaw could expose sensitive data or disrupt critical network services.

A separate advisory highlights CVE-2025-53521, a vulnerability in F5 BIG-IP Access Policy Manager, a solution commonly used for secure application access. Successful exploitation could allow unauthorized access to protected systems.

JPCERT/CC strongly urges system administrators and IT security teams in Japan and across Asia to apply the latest patches immediately, review their software inventories, and monitor systems for any signs of suspicious activity.

この記事を書いた人 Wrote this article

Chris Nakagawa

Biographical Info: -Building international financial networks, head of IT infrastructure projects including networks. -Involved in international financial infrastructure consulting, operational design for a major telecom company in Hong Kong. - Experience as a security analyst, providing integrated security system solutions. - Expertise advisory services for planning security countermeasures against advanced cyber attacks, as well as supervisory services focusing on incident response. - Advisory for CISO/CTO/CEO security guidelines / policy creation. - Supervising for SOC/CSIRT - Speaker at international conferences, author of numerous books, etc. - Certification : CISSP/GIAC/GCIA/CEH

TOP