VDB

GCVE-110-NCSC-2026-394

GCVE-110-NCSC-2026-394
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published September 27, 2026
An input validation vulnerability in Citrix NetScaler ADC and Gateway allows unauthenticated attackers to execute arbitrary commands remotely.

Weaknesses (CWE)

CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-342Predictable Exact Value from Previous ValuesCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Citrixvers:unknown/*——

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›