Citrix Patches Critical Authentication Bypass Flaw in NetScaler Products
Citrix has released security updates to fix two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, products widely used by businesses to manage secure remote access and network traffic. One of the flaws is rated critical and could allow attackers to bypass authentication controls on certain configurations, including FIPS and NDcPP builds, as well as SecurAccess deployments.
Because these systems often sit at the front line of a business's network, controlling who can log in and access internal resources, a successful exploit could give attackers a direct path into sensitive systems without needing valid credentials. Citrix has not indicated whether the flaws are being actively exploited, but authentication bypass vulnerabilities are frequently targeted quickly once details become public.
Organisations using customer-managed NetScaler ADC or Gateway deployments, particularly those running FIPS, NDcPP, or SecurAccess configurations, should review Citrix's advisory and apply the available updates as soon as possible. Delaying patches on internet-facing gateway devices significantly increases the risk of compromise.