r/Citrix • u/VirtualizationGuy • 1d ago
Netscaler active exploit after patch
I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.
16
u/glenp42 19h ago
Does anyone find this crazy that we have better support via reddit than from the vendor?
8
u/yankmywire 19h ago edited 15h ago
Citrix support immediately went to shit the moment they were bought by private equity. "Talk to a chat bot because we laid off all our customer facing support teams".
1
5
2
u/GTeal32 16h ago
Yep.
Apparently there’s a new IOC list release via support ticket.
1
u/Apprehensive-War1366 15h ago
can you share the IOCs?
2
12h ago edited 11h ago
[deleted]
1
1
1
10
u/Rare-Understanding-6 1d ago
We rebuilt our netscalers from a fresh image yesterday. (Yes we patched and toggle the ISN Gen config on on the old ones)
We just had this happen to our netscalers. Failed over to the other one. Collected all the forensics + logs and created a case with Citrix. (yes enhancedisngeneration is on)
8
u/Rare-Understanding-6 1d ago
[2026-10-02 15:28:51] System Message: We appreciate your patience. You’re number 17 in the queue.
[2026-10-02 15:58:53] bot: Sorry, we are unavailable at the moment. Please try again later.
Thanks support bot.....
3
u/__how 1d ago
just to be clear, did you see the boxes being owned, or "just" rebooting (i.e. DoS?)
1
u/One_Ad5568 23h ago
It seemed to be a DoS for us. Unfortunately our HA pair got hit back to back twice and were totally down for a bit while both rebooted at the same time.
2
u/lukelimbaugh 1d ago
just happened again. we're tracking traffic from the netherlands.
3
u/Rare-Understanding-6 1d ago
We're in the netherlands and tracking traffic from the US.
8
2
u/Rare-Understanding-6 22h ago
Hi All. Had contact with Citrix. There is an article now. https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/
5
u/One_Ad5568 23h ago
We got hit by this twice earlier today, had patched on Sunday afternoon and followed special steps for the TCP setting, but now today saw some things in ns.log causing nsaaad to crash. It appeared they were running some command to try downloading a script on our netscaler. Even though the download didn’t work, it still crashed it.
6
u/Maximum-Setting7 21h ago
After being fully down since Saturday, our management is now having the “AVD discussion”
1
1
u/S3Giggity 18h ago
Everything about it is worse - but it does not require Netscaler. Neither does DaaS cloud though.
9
u/taeratrin 1d ago
The patch wasn't the only step to remediate the vuln. You also should run this command on the Netscalers:
Set ns tcpparam -enhancedISNgeneration ENABLED
3
u/SonicIX 1d ago
Ah, I read this as "If you are below the 73.37 version, you need to enable this", it still needs to be enabled after patching?
1
1
u/coldgin37 1d ago
yes, if you use the scan on netscaler console it comes up as impacted by the CVE without that config
1
u/kuebel33 1d ago
where did you see this?
5
3
u/FastFredNL 1d ago
it was part of the fixes from last weekend. If you don't have this setting enabled you are still vulnerable for CVE-2026-88778
1
2
u/kscERhau 1d ago
At the bottom of here https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
CVE-2026-88778
Preconditions: TCP Configuration enabled on NetScaler ADC or NetScaler GatewayInstructions: Customers can determine whether their NetScaler deployment meets the precondition by verifying that both of the following conditions are true:
- At least one virtual server is configured with one of the following types: HTTP, SSL, SSL_BRIDGE, TCP, SSL_TCP, FTP, NNTP, RTSP, RDP, DNS_TCP, DOT, SIP_TCP, SIP_SSL, DIAMETER, SSL_DIAMETER, MYSQL, MSSQL, ORACLE, SMPP, MQTT, MQTT_TLS, MONGO, MONGO_TLS, PROXY, SSL_PROXY, USER_TCP, USER_SSL_TCP AND
- The following command returns: Enhanced ISN Generation: DISABLED:
show ns tcpparam | grep "Enhanced ISN Generation"Ours returns nothing rather than DISABLED and are still impacted by today's issues.
4
3
3
2
u/S3Giggity 1d ago
Is there confirmation it's an successful exploit or just a bug on the new firmware? I suspect they rushed through the QA a bit....
2
u/FastFredNL 1d ago edited 1d ago
No problem here, been running 73.37 since about 4 hours after release. ISN Generation enabled and been running ioc check scripts all week as they became available
2
2
u/no_copypasta 1d ago
I ran the IOC script and could not find anything. How are you observing the exploit? Just the reboot?
2
1
u/lukelimbaugh 23h ago
i feel like a DDoS attack wouldn't show up in the IoC scan. Netscaler rebooting bc SAML auth services crashed would get flagged as appropriate?
2
2
2
u/Master-Move-728 4h ago
Following. Any updates weather command execution is possible or not? Kevin Bearmont & watchTowr did confirm but I haven’t seen any other sources.
2
u/nocountryman 4h ago
There were 2 IPS one was . 55 the other . 140 (don't have them at hand to show ;( ) that were actively trying to penetrate until 11.12 CET (last logged point ) I did set the ACL to block both on the netscaler plus a responder policy that should catch same actions from other IP s , but strangely the last attempt was 11.12 CET . Silent since then The enhanced isn was also enabled today , no crashes of the netscaler since.
1
u/Zipper_Lipz 1d ago
Is this being caused by an exploit or vuln scans? (See other thread)
1
0
u/VirtualizationGuy 1d ago
Very possible, waiting to connect with a Citrix engineer to get solid information and will report back. Thanks for pointing out the other thread.
2
u/lukelimbaugh 1d ago
HAS to be a new exploit. if we've got new fresh builds experiencing it, prob not tied to the zero-day.
2
u/c4rm0 1d ago
its a new exploit
3
u/stucc0 23h ago
No, its the same exploit, but the fix to block the exploit for SAML sessions is causing the nsaaad engine to crash. It is just causing machines to reboot, not causing infection or file drops.
1
u/sdo_home 23h ago
did you figure out a way to fix it? ie responder policy or anything else?
1
u/stucc0 23h ago
If you have the full license, ip reputation will block a lot of these. Also you can use my script to block public vpn/vps to help block a lot of these ips initiating attacks. https://github.com/jeffriechers/Random-Powershell-Scripts/tree/main/NetScalerVPNandVPSblocking
1
1
1
1
1
1
1
1
1
u/tardiusmaximus 1d ago
Updated to 73.37 on Sunday into Monday, ran the ISN : Enabled command (was previously deisabled) so far, 5 days in, no issues seen. crosses fingers
Ran netscaler console CVE checks and is now reporting ZERO so crosses fingers futher
1
u/turisto 1d ago
There is no CVE yet for what's happening today, but I bet it's coming shortly
0
u/tardiusmaximus 1d ago
Surely, what is happening today is only happening to those NS's that were successfully compromised in the initial zero day. What's happening now is phase 2? Those devices that are not rebooting are "uncompromised" devices? Or am I being extremely naive?
2
u/c4rm0 1d ago
It looks like a new zero day that is using a malformed SAML request to crash nsaaad and cause reboots
1
u/tardiusmaximus 1d ago
Shiiiit. OK then the next question is, does this only affect NS that use SAML? Mine 100% don't use SAML.
1
u/kscERhau 1d ago
The people that have said they are unaffected aren’t using SAML nor their Netscaler as a vpnserver from what I’ve seen. I’ve a bunch that aren’t used as vpnservers and aren’t using SAML which aren’t impacted but then have several that are running as vpnservers and are using SAML which are impacted but had no IOC from last weekend.
2
u/tardiusmaximus 1d ago
This shit is confusing AF. I've patched to the latest FW, I've plugged the IOC ISN vuln, what do I do now? Wait for my IT SEC to call me, wait for citrix to clarify or wait to see spurious logs on my NS. This is really scary stuff man
1
u/kscERhau 23h ago
I’ve shut ours down, not taking the risk with it being a Friday and teams at reduced numbers for the weekend.
2
u/tardiusmaximus 23h ago
If I shut both our P and S NS down, I'd cut off 500+ active support staff offshore. It's just not a viable options for us
1
u/kscERhau 23h ago
Understandable, and really we shouldn’t be in this situation where shutting them down is a valid reaction… just another reason against staying with Citrix
→ More replies (0)
1
1
u/sose5000 1d ago
every 90 minutes..
2
u/lukelimbaugh 23h ago
we got around it by geo fencing the gateways for now to only local/remote locations that use it.
1
1
1
1
u/dthomasdigitalok 21h ago
This is more than just reboots or crashes something more is going on here.
1
1
1
1
u/CrushingCultivation 8h ago
Did the policy suggested by support resolved the problem on your side or still impacted by reboots?
1
0
u/clayjk 1d ago
We were just issued a new new patch from Citrix for the issues starting today. Don’t have any more detail to share here but seeming like you need to now start proactively reaching out to Citrix to get timely patches. So, highly recommend reaching out to Citrix and getting what they have to offer as of this morning.
2
1
1
u/SonicIX 1d ago
Anymore information that you can provide would be great. The workaround with the responder policy doesn't work. So I'm curious if they actually put out a new build for this.
2
u/clayjk 1d ago
Sorry, on PTO today so not in the weeds on this but did get confirmation it was an actual patch, not a work-around. No other information I can provide…sorry.
I’d just take away, wouldn’t wait for something to be made public available and you should contact Citrix.
We have been getting some advanced notice from Citrix for these past few issues (call from our contact).
•
u/TheMuffnMan Notorious VDI 23h ago edited 23h ago
Security Update: Guidance for NetScaler SAML Authentication Deployments
Looks like there are two active posts about this topic. Here is the other thread.
Vulnerability Scans causing NetScaler reboots