Who is affected
Citrix NetScaler ADC and NetScaler Gateway installations configured to provide authentication services are affected. This includes deployments operating as an AAA virtual server, SSL VPN gateway, ICA Proxy, CVPN, or RDP Proxy. The vulnerability allows unauthenticated remote access to bypass authentication entirely, regardless of configured credentials or multi-factor authentication policies.
How to check whether this touches you
- Search your asset inventory for Citrix NetScaler ADC or NetScaler Gateway appliances.
- Establish whether any of these appliances are configured as an AAA virtual server, SSL VPN endpoint, ICA Proxy, CVPN, or RDP Proxy by reviewing configuration documentation or connecting to the management interface.
- Confirm network reachability by attempting to reach the authentication endpoints from outside your organisation's network perimeter (or ask your network team whether these services are published externally).
- Retrieve the running firmware version from the appliance (Administration > System > Software Releases) and compare it against Citrix's patch advisory; note that backported fixes exist and version alone is not conclusive proof of protection.
What to do
- Obtain Citrix's latest security advisory and patch guidance immediately; federal systems must comply with BOD 26-04 prioritisation timelines (remediation due 2026-09-12 from CISA's record date).
- If you cannot patch immediately, restrict network access to these appliances by IP allowlist, firewall rules, or moving them behind an additional authentication layer; document which endpoints remain exposed and to whom.
- Enable comprehensive logging on affected appliances (session logs, authentication logs, and admin activity logs) and configure alerts on authentication failures or suspicious bypass attempts.
- If the appliance is a cloud service and patching is unavailable from the vendor, evaluate whether discontinuation is necessary under BOD 26-04 guidance.
- Escalate to your change management and security leadership; authentication bypass on a gateway-tier appliance is a critical risk requiring expedited patching.
If you find you were exposed
Exploitation of an authentication-bypass flaw typically precedes public disclosure; check historical logs covering at least the past six months for anomalous authentication events, failed logins followed by successful sessions without credentials, or access from unexpected geographies or IP ranges. Log retention is often the limiting factor, so contact your SIEM operator or appliance administrator immediately to preserve logs before they roll off. Compare user login records against known business activity to identify sessions that may represent compromise. If you identify suspicious activity, assume internal compromise and initiate incident response procedures including credential review and lateral movement detection.