Citrix NetScaler ADC/Gateway improper input validation vulnerability leading to remote command execution
Before Citrix NetScaler ADC 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS, and NDcPP, and before Citrix NetScaler Gateway 14.1-73.37 and 13.1-64.23, there is an improper input validation (CWE-20) security defect. The vulnerability lets an unauthenticated attacker craft a malicious request and execute arbitrary commands on the server. Citrix NetScaler ADC and Gateway lack an effective validation mechanism when handling certain input, so an attacker can bypass security restrictions and take direct control of the underlying system. It affects every Citrix NetScaler ADC and Gateway user who has not updated to the specified fixed versions, including enterprise application delivery controller and gateway deployments. An attacker needs no authentication to trigger the vulnerability remotely and can take complete control of the system.
Component
Citrix NetScaler ADC (application delivery controller) and NetScaler Gateway are enterprise network infrastructure components that provide application delivery optimization, load balancing, and secure access gateway services.
Risks
Complete system control: An unauthenticated attacker can execute arbitrary commands and fully control the affected Citrix server, including reading sensitive data, changing configuration, or installing malware
Unauthenticated remote attack: An attacker needs no credentials to launch the attack, which greatly lowers the barrier
Lateral movement: Once the server is controlled, an attacker can use it as a foothold to penetrate the internal network further
Restrict access to the Citrix management interface and specific ports at the firewall or WAF
Monitor abnormal process starts and command-execution logs on the server so intrusion can be found promptly
CVE-2026-100886
CVSS
10.0 Critical
2026-09-28
Seetong Debug Service remote authentication bypass vulnerability leading to remote code execution
In Seetong T8108, T8108P, T8116, and T8232 firmware 4.6.1.4-build202604241011, an unknown function in the Debug Service component has an improper authentication (CWE-287) security defect. The operation leads to improper authentication, and an attacker can attack remotely. Exploit code has been published and may already be in use. The vendor was contacted early in disclosure but made no response. The vulnerability affects every Seetong device running the affected firmware. An attacker can exploit it remotely with no user interaction, which can result in complete loss of system control.
Component
Seetong is a vendor of security surveillance equipment such as network video recorders (NVR) and digital video recorders (DVR). Its devices are widely used for video surveillance.
Risks
From ordinary user to administrator: If access control on the victim device is not configured correctly, an attacker can obtain device administration privileges
Complete system control: An attacker can use this vulnerability to bypass authentication and perform arbitrary operations on the victim device, including viewing, changing, or deleting surveillance data, or creating a new account with full privileges
No-user-interaction attack: The attack can be launched remotely. Exploit code is public, so an attacker can trigger the vulnerability without inducing the user to take any extra action
Immediately isolate affected Seetong devices so they are not exposed on the public network
Enable a network access-control list (ACL) and restrict access to the Debug Service port
Package Poisoning
10
Package Poisoning
npm2026-09-28
@bb1omega23/test-paket@1.0.3
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
07100c42eab6cdbc930cccf866342413
Package Poisoning
npm2026-09-28
@consts/links@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
252ff982315fd1f56107fc19dee944a3
Package Poisoning
npm2026-09-28
@wbnr/design-kit@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
1f75b7cbeeca95a7cea1775f2c006725
Package Poisoning
npm2026-09-28
@wbnr/lottiefiles-loader@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
2558d1f6b776a1b46dc2c964a4474727
Package Poisoning
npm2026-09-28
kalasnik-npm-simple-test@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
14791321553017f361ceae134eb618f5
Package Poisoning
npm2026-09-28
kjj81@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
9b47f5cf9d32c2320c1d029cc7091190
Package Poisoning
npm2026-09-28
riot-private@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
8140c136cd355f6f1d606b8726b9a387
Package Poisoning
npm2026-09-28
tanksync@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
37c0178e946b64a0a82c43c5ab52ecb2
Package Poisoning
npm2026-09-28
vinzzsync-wacli@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.
MD5
30322c1833347a7e5378e2fa4ae8aea3
Package Poisoning
npm2026-09-28
wbnr-probe-visible-check@>= 0
flagged as malicious
This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.