Input validation error in Citrix Netscaler ADC and Citrix NetScaler Gateway - #VU152266

 

Input validation error in Citrix Netscaler ADC and Citrix NetScaler Gateway - #VU152266

Published: September 27, 2026


Vulnerability identifier: #VU152266
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an unspecified issue. A remote non-authenticated attacker can send specially crafted requests to the affected system and execute arbitrary code.

Note, the vulnerability is being actively exploited in the wild as per watchTowr sources.


Affected software

Citrix Netscaler ADC
Citrix NetScaler Gateway

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins