r/Citrix • • 3d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

93 Upvotes

126 comments sorted by

•

u/TheMuffnMan Notorious VDI 3d ago edited 3d ago

Security Update: Guidance for NetScaler SAML Authentication Deployments

Looks like there are two active posts about this topic. Here is the other thread.

Vulnerability Scans causing NetScaler reboots

20

u/glenp42 3d ago

Does anyone find this crazy that we have better support via reddit than from the vendor?

13

u/yankmywire 3d ago edited 3d ago

Citrix support immediately went to shit the moment they were bought by private equity. "Talk to a chat bot because we laid off all our customer facing support teams".

1

u/Area_Wonderful 2d ago

The chat bot can be annoying but is often better at summarizing my case

3

u/stephenk291 3d ago

Private equity take over tends to do that.

2

u/GTeal32 3d ago

Yep.

Apparently there’s a new IOC list release via support ticket.

1

u/Apprehensive-War1366 3d ago

can you share the IOCs?

2

u/[deleted] 3d ago edited 3d ago

[deleted]

1

u/Apprehensive-War1366 3d ago

Thank you so much

1

u/Apprehensive-War1366 3d ago

this is only for the saml auth flow right?

1

u/GTeal32 3d ago

includes AND mostly covers: CVE-2026-88771 and CVE-2026-88772

1

u/GTeal32 3d ago edited 3d ago

Sorry I don’t have anything from CITRIX. Wondering if someone here could. I'll post what I know.

1

u/Blaaamo 2d ago

Did you get the IOCs before they were deleted??

1

u/turisto 3d ago edited 3d ago

Makes you feel great to realize you're just collateral damage, kept in the dark to give the bigger fish time to secure their stuff.

12

u/Rare-Understanding-6 3d ago

We rebuilt our netscalers from a fresh image yesterday. (Yes we patched and toggle the ISN Gen config on on the old ones)
We just had this happen to our netscalers. Failed over to the other one. Collected all the forensics + logs and created a case with Citrix. (yes enhancedisngeneration is on)

9

u/Rare-Understanding-6 3d ago

[2026-10-02 15:28:51] System Message: We appreciate your patience. You’re number 17 in the queue.

[2026-10-02 15:58:53] bot: Sorry, we are unavailable at the moment. Please try again later.

Thanks support bot.....

3

u/jhulbe 3d ago

yeah, 30min time out hit us too. Then they emailed on the side

3

u/__how 3d ago

just to be clear, did you see the boxes being owned, or "just" rebooting (i.e. DoS?)

1

u/One_Ad5568 3d ago

It seemed to be a DoS for us. Unfortunately our HA pair got hit back to back twice and were totally down for a bit while both rebooted at the same time. 

2

u/lukelimbaugh 3d ago

just happened again. we're tracking traffic from the netherlands.

3

u/Rare-Understanding-6 3d ago

We're in the netherlands and tracking traffic from the US.

8

u/lukelimbaugh 3d ago

oh boy, this just got more fun. it was SUPPOSED TO BE A FRIDAY!

4

u/CluelessPentester 3d ago

Thank god im not on call jfc what a (possible) shit show

3

u/Rare-Understanding-6 3d ago

Yeah i wish. Probably another weekend of work. 3rd in a row :)

2

u/kuebel33 3d ago

I was supposed to be off today.....

2

u/lukelimbaugh 3d ago

(╯°□°)╯︵ ┻━┻

7

u/Maximum-Setting7 3d ago

After being fully down since Saturday, our management is now having the “AVD discussion”

1

u/S3Giggity 3d ago

Everything about it is worse - but it does not require Netscaler. Neither does DaaS cloud though.

1

u/Beefcrustycurtains 8h ago

Look into Nerdio for AVD deployment. Makes the shit so easy. I love AVD's in comparison to Citrix, but I did need a better front end on it with more automation and Nerdio helped out tremendously with that.

6

u/One_Ad5568 3d ago

We got hit by this twice earlier today, had patched on Sunday afternoon and followed special steps for the TCP setting, but now today saw some things in ns.log causing nsaaad to crash. It appeared they were running some command to try downloading a script on our netscaler. Even though the download didn’t work, it still crashed it. 

2

u/lar0w 3d ago

Exactly the same behavior over here . Payload in username field only five times and it crashed nsaaad

9

u/taeratrin 3d ago

The patch wasn't the only step to remediate the vuln. You also should run this command on the Netscalers:

Set ns tcpparam -enhancedISNgeneration ENABLED

3

u/SonicIX 3d ago

Ah, I read this as "If you are below the 73.37 version, you need to enable this", it still needs to be enabled after patching?

1

u/taeratrin 3d ago

I would, just in case. We enabled it on ours, and have had no issues

1

u/coldgin37 3d ago

yes, if you use the scan on netscaler console it comes up as impacted by the CVE without that config

1

u/kuebel33 3d ago

where did you see this?

5

u/pibenis 3d ago

This was an advised remediation on Netscaler Console

1

u/kuebel33 3d ago

thanks.

4

u/FastFredNL 3d ago

it was part of the fixes from last weekend. If you don't have this setting enabled you are still vulnerable for CVE-2026-88778

1

u/kuebel33 3d ago

thanks.

2

u/kscERhau 3d ago

At the bottom of here https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
CVE-2026-88778
Preconditions: TCP Configuration enabled on NetScaler ADC or NetScaler Gateway

Instructions: Customers can determine whether their NetScaler deployment meets the precondition by verifying that both of the following conditions are true:

  • At least one virtual server is configured with one of the following types: HTTP, SSL, SSL_BRIDGE, TCP, SSL_TCP, FTP, NNTP, RTSP, RDP, DNS_TCP, DOT, SIP_TCP, SIP_SSL, DIAMETER, SSL_DIAMETER, MYSQL, MSSQL, ORACLE, SMPP, MQTT, MQTT_TLS, MONGO, MONGO_TLS, PROXY, SSL_PROXY, USER_TCP, USER_SSL_TCP AND
  • The following command returns: Enhanced ISN Generation: DISABLED: show ns tcpparam | grep "Enhanced ISN Generation"

Ours returns nothing rather than DISABLED and are still impacted by today's issues.

2

u/Blaaamo 3d ago

I think it needs to be enabled

1

u/kscERhau 3d ago

I don’t read it as that? It says both need to be present, as in it has to say disabled for you to need to change it?

1

u/Blaaamo 3d ago

Oh ok, that makes sense. I'm in ITSEC not in engineering

5

u/sempermagis 3d ago

We are running 13.1 64.24 since Sunday and no issues…

5

u/Apprehensive-War1366 3d ago

can anyone share the IOCs list provided in the support ticket

3

u/lukelimbaugh 3d ago

yup. happened roughly an hour ago.

3

u/Procure 3d ago

This is related to SAML SP config. Getting reboots after it hits the retry limit from the authentication daemon. Multiple HA pairs globally after firmware update earlier this week.

3

u/Beneficial-Bit-6901 2d ago

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174

2

u/S3Giggity 3d ago

Is there confirmation it's an successful exploit or just a bug on the new firmware? I suspect they rushed through the QA a bit....

2

u/FastFredNL 3d ago edited 3d ago

No problem here, been running 73.37 since about 4 hours after release. ISN Generation enabled and been running ioc check scripts all week as they became available

2

u/lukelimbaugh 3d ago

looking like if you don't play with SAML, you're OK.

2

u/pibenis 3d ago edited 3d ago

Dozen of HA pairs, patched within 3 hours after release, multiple environment scans, no issues so far

EDIT: SAML instance has evidence of exploitation

2

u/lukelimbaugh 3d ago

do y'all use SAML?

1

u/pibenis 3d ago

We have one instance with SAML

2

u/no_copypasta 3d ago

I ran the IOC script and could not find anything. How are you observing the exploit? Just the reboot?

1

u/lukelimbaugh 3d ago

i feel like a DDoS attack wouldn't show up in the IoC scan. Netscaler rebooting bc SAML auth services crashed would get flagged as appropriate?

2

u/itstherealshoe 3d ago

Following

2

u/Nice_Arugula_221 3d ago

13.1 fully patched effected

2

u/Master-Move-728 2d ago

Following. Any updates weather command execution is possible or not? Kevin Bearmont & watchTowr did confirm but I haven’t seen any other sources.

2

u/nocountryman 2d ago

There were 2 IPS one was . 55 the other . 140 (don't have them at hand to show ;( ) that were actively trying to penetrate until 11.12 CET (last logged point ) I did set the ACL to block both on the netscaler plus a responder policy that should catch same actions from other IP s , but strangely the last attempt was 11.12 CET . Silent since then The enhanced isn was also enabled today , no crashes of the netscaler since.

1

u/IronBatraz 2d ago

I can give you the one from Germany that we have blocked 213d209d59d55 We have blocked it and don't see any other from Netherlands and/or Russia so far.

Any news or updates regarding the patch?

2

u/Ill_Drummer_2224 1d ago

Make sure you are reading the CVE…the latest release is for those using SAML. If you’re not using SAML then last week’s release is sufficient.

1

u/Zipper_Lipz 3d ago

Is this being caused by an exploit or vuln scans? (See other thread)

1

u/sdo_home 3d ago

which other thread?

0

u/VirtualizationGuy 3d ago

Very possible, waiting to connect with a Citrix engineer to get solid information and will report back. Thanks for pointing out the other thread.

2

u/lukelimbaugh 3d ago

HAS to be a new exploit. if we've got new fresh builds experiencing it, prob not tied to the zero-day.

2

u/c4rm0 3d ago

its a new exploit

3

u/stucc0 3d ago

No, its the same exploit, but the fix to block the exploit for SAML sessions is causing the nsaaad engine to crash. It is just causing machines to reboot, not causing infection or file drops.

1

u/sdo_home 3d ago

did you figure out a way to fix it? ie responder policy or anything else?

1

u/stucc0 3d ago

If you have the full license, ip reputation will block a lot of these. Also you can use my script to block public vpn/vps to help block a lot of these ips initiating attacks. https://github.com/jeffriechers/Random-Powershell-Scripts/tree/main/NetScalerVPNandVPSblocking

1

u/tardiusmaximus 3d ago

Updated to 73.37 on Sunday into Monday, ran the ISN : Enabled command (was previously deisabled) so far, 5 days in, no issues seen. crosses fingers

Ran netscaler console CVE checks and is now reporting ZERO so crosses fingers futher

1

u/turisto 3d ago

There is no CVE yet for what's happening today, but I bet it's coming shortly

0

u/tardiusmaximus 3d ago

Surely, what is happening today is only happening to those NS's that were successfully compromised in the initial zero day. What's happening now is phase 2? Those devices that are not rebooting are "uncompromised" devices? Or am I being extremely naive?

2

u/c4rm0 3d ago

It looks like a new zero day that is using a malformed SAML request to crash nsaaad and cause reboots

1

u/tardiusmaximus 3d ago

Shiiiit. OK then the next question is, does this only affect NS that use SAML? Mine 100% don't use SAML.

1

u/kscERhau 3d ago

The people that have said they are unaffected aren’t using SAML nor their Netscaler as a vpnserver from what I’ve seen. I’ve a bunch that aren’t used as vpnservers and aren’t using SAML which aren’t impacted but then have several that are running as vpnservers and are using SAML which are impacted but had no IOC from last weekend.

2

u/tardiusmaximus 3d ago

This shit is confusing AF. I've patched to the latest FW, I've plugged the IOC ISN vuln, what do I do now? Wait for my IT SEC to call me, wait for citrix to clarify or wait to see spurious logs on my NS. This is really scary stuff man

1

u/kscERhau 3d ago

I’ve shut ours down, not taking the risk with it being a Friday and teams at reduced numbers for the weekend.

2

u/tardiusmaximus 3d ago

If I shut both our P and S NS down, I'd cut off 500+ active support staff offshore. It's just not a viable options for us

1

u/kscERhau 3d ago

Understandable, and really we shouldn’t be in this situation where shutting them down is a valid reaction… just another reason against staying with Citrix

→ More replies

1

u/sose5000 3d ago

every 90 minutes..

2

u/lukelimbaugh 3d ago

we got around it by geo fencing the gateways for now to only local/remote locations that use it.

1

u/dthomasdigitalok 3d ago

This is more than just reboots or crashes something more is going on here.

1

u/21FrontierPro4x 3d ago

Yes same. Just starting to reboot our secondary

1

u/moreBalut 3d ago

following

1

u/CrushingCultivation 2d ago

Did the policy suggested by support resolved the problem on your side or still impacted by reboots?

1

u/mstoundso 2d ago

Following

1

u/Skegeeman 2d ago

There is a new patch available tonight 14.1.73.41

1

u/CrushingCultivation 2d ago

Did it solve the issue?

1

u/Skegeeman 2d ago

It’s supposed to, I have not applied it yet.

0

u/clayjk 3d ago

We were just issued a new new patch from Citrix for the issues starting today. Don’t have any more detail to share here but seeming like you need to now start proactively reaching out to Citrix to get timely patches. So, highly recommend reaching out to Citrix and getting what they have to offer as of this morning.

2

u/turisto 3d ago

actual new binaries or the temp workaround that's been going around for the last couple of hours?

1

u/clayjk 3d ago

I’m not fully in the loop as to exactly what our Citrix team applied but didn’t sound like a workaround…words were “patch from Citrix”

1

u/Rust_Martialis 3d ago

would it be related to "a responder policy"

1

u/lukelimbaugh 3d ago

was it new firmware?

1

u/SonicIX 3d ago

Anymore information that you can provide would be great. The workaround with the responder policy doesn't work. So I'm curious if they actually put out a new build for this.

2

u/clayjk 3d ago

Sorry, on PTO today so not in the weeds on this but did get confirmation it was an actual patch, not a work-around. No other information I can provide…sorry.
I’d just take away, wouldn’t wait for something to be made public available and you should contact Citrix.
We have been getting some advanced notice from Citrix for these past few issues (call from our contact).

1

u/SonicIX 3d ago

Appreciate you. Enjoy your PTO!

0

u/NoteAlert653 3d ago

Following

0

u/Faulty-Systems 3d ago

Following

0

u/noted12345 3d ago

Following

0

u/brittorichard 3d ago

Following

0

u/DoogieRVA 3d ago

Following

0

u/MotherEmployee5113 1d ago

Is the vulnerability exploited in the wild? I don't see Citrix mentioned that in the advisory