Executive brief
Citrix NetScaler is a critical networking appliance used by enterprises to manage user authentication and provide secure remote access through VPN and proxy services. This vulnerability allows attackers to completely bypass authentication and gain unauthorized access to protected applications and networks without valid credentials, potentially exposing sensitive business systems and data to compromise.
Technical details
The vulnerability is an authentication bypass flaw in Citrix NetScaler ADC and NetScaler Gateway that affects systems configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). The vulnerability exists due to improper handling of an alternate authentication path or channel, allowing unauthenticated remote attackers to bypass the authentication mechanism without valid credentials. The attack is network-accessible and requires no prior authentication or user interaction. Successful exploitation grants unauthorized access to gateway functionality and protected resources. The vulnerability has been observed exploited in the wild, indicating active threat actor activity. Patched versions and mitigation guidance from Citrix should be applied immediately.
Affected products
- Citrix NetScaler ADC
- Citrix NetScaler Gateway
Timeline
- 2026-09-09: disclosed
- exploited: Observed exploited in wild