An unauthenticated attacker reaching a NetScaler AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) can walk straight past the login step, and CISA confirms this is already being exploited.