Threat Intelligence

Citrix Patches Critical Authentication Bypass Flaw in NetScaler Products

The Hacker News · 20 Aug 2026
Key Takeaway If your business uses Citrix NetScaler ADC or Gateway, apply the latest security updates immediately to close this authentication bypass risk.

Citrix has released security updates to fix two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, products widely used by businesses to manage secure remote access and network traffic. One of the flaws is rated critical and could allow attackers to bypass authentication controls on certain configurations, including FIPS and NDcPP builds, as well as SecurAccess deployments.

Because these systems often sit at the front line of a business's network, controlling who can log in and access internal resources, a successful exploit could give attackers a direct path into sensitive systems without needing valid credentials. Citrix has not indicated whether the flaws are being actively exploited, but authentication bypass vulnerabilities are frequently targeted quickly once details become public.

Organisations using customer-managed NetScaler ADC or Gateway deployments, particularly those running FIPS, NDcPP, or SecurAccess configurations, should review Citrix's advisory and apply the available updates as soon as possible. Delaying patches on internet-facing gateway devices significantly increases the risk of compromise.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.