Back

CRITICAL KEV

A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

Published Sep 27, 2026 ·Due Sep 30, 2026

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (12)
  1. CISA ADP
    • SSVC automatable changed from no to yes
  2. CISA ADP
    • SSVC automatable changed from yes to no
  3. CISA ADP
    • SSVC automatable changed from no to yes
  4. CISA ADP
    • SSVC automatable changed from yes to no
  5. CISA ADP
    • SSVC automatable changed from no to yes
  6. CISA ADP
    • SSVC automatable changed from yes to no
  7. CISA ADP
    • SSVC automatable changed from no to yes
  8. CISA ADP
    • SSVC automatable changed from yes to no
  9. CISA ADP
    • SSVC automatable changed from no to yes
  10. CISA ADP
    • SSVC automatable changed from yes to no
  11. CISA ADP
    • SSVC automatable changed from no to yes
  12. CISA ADP
    • SSVC automatable changed from yes to no
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NetScaler
Published Sep 27, 2026
Updated Sep 29, 2026
Reserved Sep 10, 2026
CISA Vulnrichment
Updated Sep 28, 2026
NVD
Status Received
Modified Sep 27, 2026
Red Hat
Severity n/a
Public date n/a