Critical authentication bypass in Citrix NetScaler ADC and Gateway
Unauthenticated auth bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) allows remote exploitation with no user interaction. Patches released August 19, 2026 for 13.1 and 14.1 branches.
- Vendor
- Citrix
- Product
- NetScaler ADC, NetScaler Gateway
- CVSS
- 9.3
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
An unauthenticated authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, carrying a CVSS v4.0 base score of 9.3. An attacker can reach the flaw remotely with no user interaction and no elevated privileges required — the full trifecta for a network-edge product.
Affected Versions
| Product | Vulnerable if running | Fixed in |
|---|---|---|
| NetScaler ADC/Gateway 14.1 | Prior to 14.1-73.32 | 14.1-73.32 |
| NetScaler ADC/Gateway 13.1 | Prior to 13.1-63.21 | 13.1-63.21 |
| NetScaler ADC FIPS 14.1 | Prior to 14.1-73.32 FIPS | 14.1-73.32 FIPS |
| NetScaler ADC 13.1-FIPS/NDcPP | Prior to 13.1-37.277 | 13.1-37.277 |
Mitigation
No workaround listed. Update to the fixed release for your branch. Citrix’s advisory CTX696939 is the authoritative patch guidance. Prioritize internet-facing Gateway appliances first.
As of August 19, 2026, no exploitation in the wild has been confirmed per Rapid7’s early technical assessment. Given the class of vulnerability and the perimeter position of these products, that status should be treated as time-limited.
