NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
RSS

2026-09-28 Daily Security Intelligence

CVE Intelligence 2

CVE-2026-88771 CVSS 10.0 Critical 2026-09-28

Citrix NetScaler ADC/Gateway improper input validation vulnerability leading to remote command execution

Before Citrix NetScaler ADC 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, 13.1.37.279 FIPS, and NDcPP, and before Citrix NetScaler Gateway 14.1-73.37 and 13.1-64.23, there is an improper input validation (CWE-20) security defect. The vulnerability lets an unauthenticated attacker craft a malicious request and execute arbitrary commands on the server. Citrix NetScaler ADC and Gateway lack an effective validation mechanism when handling certain input, so an attacker can bypass security restrictions and take direct control of the underlying system. It affects every Citrix NetScaler ADC and Gateway user who has not updated to the specified fixed versions, including enterprise application delivery controller and gateway deployments. An attacker needs no authentication to trigger the vulnerability remotely and can take complete control of the system.

Component
Citrix NetScaler ADC (application delivery controller) and NetScaler Gateway are enterprise network infrastructure components that provide application delivery optimization, load balancing, and secure access gateway services.
Risks
  • Complete system control: An unauthenticated attacker can execute arbitrary commands and fully control the affected Citrix server, including reading sensitive data, changing configuration, or installing malware
  • Unauthenticated remote attack: An attacker needs no credentials to launch the attack, which greatly lowers the barrier
  • Lateral movement: Once the server is controlled, an attacker can use it as a foothold to penetrate the internal network further
Source
Remediation
  • Restrict access to the Citrix management interface and specific ports at the firewall or WAF
  • Monitor abnormal process starts and command-execution logs on the server so intrusion can be found promptly
CVE-2026-100886 CVSS 10.0 Critical 2026-09-28

Seetong Debug Service remote authentication bypass vulnerability leading to remote code execution

In Seetong T8108, T8108P, T8116, and T8232 firmware 4.6.1.4-build202604241011, an unknown function in the Debug Service component has an improper authentication (CWE-287) security defect. The operation leads to improper authentication, and an attacker can attack remotely. Exploit code has been published and may already be in use. The vendor was contacted early in disclosure but made no response. The vulnerability affects every Seetong device running the affected firmware. An attacker can exploit it remotely with no user interaction, which can result in complete loss of system control.

Component
Seetong is a vendor of security surveillance equipment such as network video recorders (NVR) and digital video recorders (DVR). Its devices are widely used for video surveillance.
Risks
  • From ordinary user to administrator: If access control on the victim device is not configured correctly, an attacker can obtain device administration privileges
  • Complete system control: An attacker can use this vulnerability to bypass authentication and perform arbitrary operations on the victim device, including viewing, changing, or deleting surveillance data, or creating a new account with full privileges
  • No-user-interaction attack: The attack can be launched remotely. Exploit code is public, so an attacker can trigger the vulnerability without inducing the user to take any extra action
Source
Remediation
  • Immediately isolate affected Seetong devices so they are not exposed on the public network
  • Enable a network access-control list (ACL) and restrict access to the Debug Service port

Package Poisoning 10

Package Poisoning npm 2026-09-28

@bb1omega23/test-paket@1.0.3 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
07100c42eab6cdbc930cccf866342413
Package Poisoning npm 2026-09-28

@consts/links@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
252ff982315fd1f56107fc19dee944a3
Package Poisoning npm 2026-09-28

@wbnr/design-kit@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
1f75b7cbeeca95a7cea1775f2c006725
Package Poisoning npm 2026-09-28

@wbnr/lottiefiles-loader@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
2558d1f6b776a1b46dc2c964a4474727
Package Poisoning npm 2026-09-28

kalasnik-npm-simple-test@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
14791321553017f361ceae134eb618f5
Package Poisoning npm 2026-09-28

kjj81@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
9b47f5cf9d32c2320c1d029cc7091190
Package Poisoning npm 2026-09-28

riot-private@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
8140c136cd355f6f1d606b8726b9a387
Package Poisoning npm 2026-09-28

tanksync@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
37c0178e946b64a0a82c43c5ab52ecb2
Package Poisoning npm 2026-09-28

vinzzsync-wacli@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
30322c1833347a7e5378e2fa4ae8aea3
Package Poisoning npm 2026-09-28

wbnr-probe-visible-check@>= 0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
bd95e46742b62a7beab639dd0b6d981c