New MCP server — Bring vulnerability intelligence into your AI
Back to feed

CVE-2026-101000

NVDCIRCL

Published Sep 28, 2026 · today

A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Weaknesses

CWE-862CWE-863

CVSS scores

  • v4.09.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.110.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • v2.010.0AV:N/AC:L/Au:N/C:C/I:C/A:C

References

Potentially impacted assets

See if this affects your attack surface

Latest trending attack

Criticaltoday

Citrix NetScaler ADC / Gateway - Unauthenticated Authentication Bypass in AAA/VPN & Memory Corruption Remote Code Execution (RCE) or Denial of Service (DOS) & Unauthenticated Remote Code Execution (RCE) via Input Validation

Citrix NetScaler ADC and Gateway are internet-exposed edge devices providing SSL VPN, remote access, and application proxy services for enterprises. They serve as critical entry points between external users and internal network resources. CVE-2026-19490 Critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. Boasting a CVSS score of 9.3, this flaw resides in the alternative path handling of authentication mechanisms. It allows an unauthenticated remote attacker to completely circumvent authentication controls and gain unauthorized access to protected internal services without requiring legitimate user interaction or credentials. CVE-2026-88771 Extremely high-risk remote code execution (RCE) zero-day vulnerability found in Citrix NetScaler ADC and NetScaler Gateway. Rated with a critical CVSS score of 9.5, it stems from an improper input validation error (CWE-20). Because it affects all default deployment configurations without any feature prerequisites, a network-based unauthenticated attacker can exploit it to execute arbitrary commands directly on the appliance. CVE-2026-88772 Critical zero-day vulnerability affecting Citrix NetScaler ADC and Gateway instances that have Datagram Transport Layer Security (DTLS) enabled. It is caused by an improper restriction of operations within the bounds of a memory buffer, resulting in a memory overflow. With a CVSS score of 9.5, this flaw allows unauthenticated remote threat actors to trigger a total denial-of-service (DoS) condition or achieve remote code execution.

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot