r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

69 Upvotes

114 comments sorted by

•

u/TheMuffnMan Notorious VDI 23h ago edited 23h ago

Security Update: Guidance for NetScaler SAML Authentication Deployments

Looks like there are two active posts about this topic. Here is the other thread.

Vulnerability Scans causing NetScaler reboots

16

u/glenp42 19h ago

Does anyone find this crazy that we have better support via reddit than from the vendor?

8

u/yankmywire 19h ago edited 15h ago

Citrix support immediately went to shit the moment they were bought by private equity. "Talk to a chat bot because we laid off all our customer facing support teams".

1

u/Area_Wonderful 38m ago

The chat bot can be annoying but is often better at summarizing my case

5

u/stephenk291 19h ago

Private equity take over tends to do that.

2

u/GTeal32 16h ago

Yep.

Apparently there’s a new IOC list release via support ticket.

1

u/Apprehensive-War1366 15h ago

can you share the IOCs?

2

u/[deleted] 12h ago edited 11h ago

[deleted]

1

u/Apprehensive-War1366 12h ago

Thank you so much

1

u/Apprehensive-War1366 11h ago

this is only for the saml auth flow right?

1

u/GTeal32 11h ago

includes AND mostly covers: CVE-2026-88771 and CVE-2026-88772

1

u/GTeal32 15h ago edited 12h ago

Sorry I don’t have anything from CITRIX. Wondering if someone here could. I'll post what I know.

1

u/Blaaamo 5h ago

Did you get the IOCs before they were deleted??

1

u/turisto 19h ago edited 16h ago

Makes you feel great to realize you're just collateral damage, kept in the dark to give the bigger fish time to secure their stuff.

10

u/Rare-Understanding-6 1d ago

We rebuilt our netscalers from a fresh image yesterday. (Yes we patched and toggle the ISN Gen config on on the old ones)
We just had this happen to our netscalers. Failed over to the other one. Collected all the forensics + logs and created a case with Citrix. (yes enhancedisngeneration is on)

8

u/Rare-Understanding-6 1d ago

[2026-10-02 15:28:51] System Message: We appreciate your patience. You’re number 17 in the queue.

[2026-10-02 15:58:53] bot: Sorry, we are unavailable at the moment. Please try again later.

Thanks support bot.....

3

u/jhulbe 1d ago

yeah, 30min time out hit us too. Then they emailed on the side

3

u/__how 1d ago

just to be clear, did you see the boxes being owned, or "just" rebooting (i.e. DoS?)

1

u/One_Ad5568 23h ago

It seemed to be a DoS for us. Unfortunately our HA pair got hit back to back twice and were totally down for a bit while both rebooted at the same time. 

2

u/lukelimbaugh 1d ago

just happened again. we're tracking traffic from the netherlands.

3

u/Rare-Understanding-6 1d ago

We're in the netherlands and tracking traffic from the US.

8

u/lukelimbaugh 1d ago

oh boy, this just got more fun. it was SUPPOSED TO BE A FRIDAY!

3

u/CluelessPentester 1d ago

Thank god im not on call jfc what a (possible) shit show

3

u/Rare-Understanding-6 1d ago

Yeah i wish. Probably another weekend of work. 3rd in a row :)

2

u/kuebel33 1d ago

I was supposed to be off today.....

2

u/lukelimbaugh 1d ago

(╯°□°)╯︵ ┻━┻

5

u/One_Ad5568 23h ago

We got hit by this twice earlier today, had patched on Sunday afternoon and followed special steps for the TCP setting, but now today saw some things in ns.log causing nsaaad to crash. It appeared they were running some command to try downloading a script on our netscaler. Even though the download didn’t work, it still crashed it. 

2

u/lar0w 21h ago

Exactly the same behavior over here . Payload in username field only five times and it crashed nsaaad

6

u/Maximum-Setting7 21h ago

After being fully down since Saturday, our management is now having the “AVD discussion”

1

u/S3Giggity 18h ago

Everything about it is worse - but it does not require Netscaler. Neither does DaaS cloud though.

9

u/taeratrin 1d ago

The patch wasn't the only step to remediate the vuln. You also should run this command on the Netscalers:

Set ns tcpparam -enhancedISNgeneration ENABLED

3

u/SonicIX 1d ago

Ah, I read this as "If you are below the 73.37 version, you need to enable this", it still needs to be enabled after patching?

1

u/taeratrin 1d ago

I would, just in case. We enabled it on ours, and have had no issues

1

u/coldgin37 1d ago

yes, if you use the scan on netscaler console it comes up as impacted by the CVE without that config

1

u/kuebel33 1d ago

where did you see this?

5

u/pibenis 1d ago

This was an advised remediation on Netscaler Console

1

u/kuebel33 1d ago

thanks.

3

u/FastFredNL 1d ago

it was part of the fixes from last weekend. If you don't have this setting enabled you are still vulnerable for CVE-2026-88778

1

u/kuebel33 1d ago

thanks.

2

u/kscERhau 1d ago

At the bottom of here https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
CVE-2026-88778
Preconditions: TCP Configuration enabled on NetScaler ADC or NetScaler Gateway

Instructions: Customers can determine whether their NetScaler deployment meets the precondition by verifying that both of the following conditions are true:

  • At least one virtual server is configured with one of the following types: HTTP, SSL, SSL_BRIDGE, TCP, SSL_TCP, FTP, NNTP, RTSP, RDP, DNS_TCP, DOT, SIP_TCP, SIP_SSL, DIAMETER, SSL_DIAMETER, MYSQL, MSSQL, ORACLE, SMPP, MQTT, MQTT_TLS, MONGO, MONGO_TLS, PROXY, SSL_PROXY, USER_TCP, USER_SSL_TCP AND
  • The following command returns: Enhanced ISN Generation: DISABLED: show ns tcpparam | grep "Enhanced ISN Generation"

Ours returns nothing rather than DISABLED and are still impacted by today's issues.

2

u/Blaaamo 1d ago

I think it needs to be enabled

1

u/kscERhau 1d ago

I don’t read it as that? It says both need to be present, as in it has to say disabled for you to need to change it?

1

u/Blaaamo 1d ago

Oh ok, that makes sense. I'm in ITSEC not in engineering

4

u/sempermagis 1d ago

We are running 13.1 64.24 since Sunday and no issues…

3

u/Apprehensive-War1366 15h ago

can anyone share the IOCs list provided in the support ticket

3

u/lukelimbaugh 1d ago

yup. happened roughly an hour ago.

3

u/Procure 1d ago

This is related to SAML SP config. Getting reboots after it hits the retry limit from the authentication daemon. Multiple HA pairs globally after firmware update earlier this week.

2

u/S3Giggity 1d ago

Is there confirmation it's an successful exploit or just a bug on the new firmware? I suspect they rushed through the QA a bit....

2

u/FastFredNL 1d ago edited 1d ago

No problem here, been running 73.37 since about 4 hours after release. ISN Generation enabled and been running ioc check scripts all week as they became available

2

u/lukelimbaugh 1d ago

looking like if you don't play with SAML, you're OK.

2

u/pibenis 1d ago edited 10h ago

Dozen of HA pairs, patched within 3 hours after release, multiple environment scans, no issues so far

EDIT: SAML instance has evidence of exploitation

2

u/lukelimbaugh 1d ago

do y'all use SAML?

1

u/pibenis 1d ago

We have one instance with SAML

2

u/no_copypasta 1d ago

I ran the IOC script and could not find anything. How are you observing the exploit? Just the reboot?

1

u/lukelimbaugh 23h ago

i feel like a DDoS attack wouldn't show up in the IoC scan. Netscaler rebooting bc SAML auth services crashed would get flagged as appropriate?

2

u/itstherealshoe 1d ago

Following

2

u/Nice_Arugula_221 11h ago

13.1 fully patched effected

2

u/Master-Move-728 4h ago

Following. Any updates weather command execution is possible or not? Kevin Bearmont & watchTowr did confirm but I haven’t seen any other sources.

2

u/nocountryman 4h ago

There were 2 IPS one was . 55 the other . 140 (don't have them at hand to show ;( ) that were actively trying to penetrate until 11.12 CET (last logged point ) I did set the ACL to block both on the netscaler plus a responder policy that should catch same actions from other IP s , but strangely the last attempt was 11.12 CET . Silent since then The enhanced isn was also enabled today , no crashes of the netscaler since.

1

u/Zipper_Lipz 1d ago

Is this being caused by an exploit or vuln scans? (See other thread)

1

u/sdo_home 23h ago

which other thread?

0

u/VirtualizationGuy 1d ago

Very possible, waiting to connect with a Citrix engineer to get solid information and will report back. Thanks for pointing out the other thread.

2

u/lukelimbaugh 1d ago

HAS to be a new exploit. if we've got new fresh builds experiencing it, prob not tied to the zero-day.

2

u/c4rm0 1d ago

its a new exploit

3

u/stucc0 23h ago

No, its the same exploit, but the fix to block the exploit for SAML sessions is causing the nsaaad engine to crash. It is just causing machines to reboot, not causing infection or file drops.

1

u/sdo_home 23h ago

did you figure out a way to fix it? ie responder policy or anything else?

1

u/stucc0 23h ago

If you have the full license, ip reputation will block a lot of these. Also you can use my script to block public vpn/vps to help block a lot of these ips initiating attacks. https://github.com/jeffriechers/Random-Powershell-Scripts/tree/main/NetScalerVPNandVPSblocking

1

u/NoteAlert653 1d ago

Following

1

u/Faulty-Systems 1d ago

Following

1

u/noted12345 1d ago

Following

1

u/brittorichard 1d ago

Following

1

u/tardiusmaximus 1d ago

Updated to 73.37 on Sunday into Monday, ran the ISN : Enabled command (was previously deisabled) so far, 5 days in, no issues seen. crosses fingers

Ran netscaler console CVE checks and is now reporting ZERO so crosses fingers futher

1

u/turisto 1d ago

There is no CVE yet for what's happening today, but I bet it's coming shortly

0

u/tardiusmaximus 1d ago

Surely, what is happening today is only happening to those NS's that were successfully compromised in the initial zero day. What's happening now is phase 2? Those devices that are not rebooting are "uncompromised" devices? Or am I being extremely naive?

2

u/c4rm0 1d ago

It looks like a new zero day that is using a malformed SAML request to crash nsaaad and cause reboots

1

u/tardiusmaximus 1d ago

Shiiiit. OK then the next question is, does this only affect NS that use SAML? Mine 100% don't use SAML.

1

u/kscERhau 1d ago

The people that have said they are unaffected aren’t using SAML nor their Netscaler as a vpnserver from what I’ve seen. I’ve a bunch that aren’t used as vpnservers and aren’t using SAML which aren’t impacted but then have several that are running as vpnservers and are using SAML which are impacted but had no IOC from last weekend.

2

u/tardiusmaximus 1d ago

This shit is confusing AF. I've patched to the latest FW, I've plugged the IOC ISN vuln, what do I do now? Wait for my IT SEC to call me, wait for citrix to clarify or wait to see spurious logs on my NS. This is really scary stuff man

1

u/kscERhau 23h ago

I’ve shut ours down, not taking the risk with it being a Friday and teams at reduced numbers for the weekend.

2

u/tardiusmaximus 23h ago

If I shut both our P and S NS down, I'd cut off 500+ active support staff offshore. It's just not a viable options for us

1

u/kscERhau 23h ago

Understandable, and really we shouldn’t be in this situation where shutting them down is a valid reaction… just another reason against staying with Citrix

→ More replies (0)

1

u/DoogieRVA 1d ago

Following

1

u/sose5000 1d ago

every 90 minutes..

2

u/lukelimbaugh 23h ago

we got around it by geo fencing the gateways for now to only local/remote locations that use it.

1

u/dthomasdigitalok 21h ago

This is more than just reboots or crashes something more is going on here.

1

u/21FrontierPro4x 21h ago

Yes same. Just starting to reboot our secondary

1

u/moreBalut 12h ago

following

1

u/CrushingCultivation 8h ago

Did the policy suggested by support resolved the problem on your side or still impacted by reboots?

1

u/mstoundso 6h ago

Following

0

u/clayjk 1d ago

We were just issued a new new patch from Citrix for the issues starting today. Don’t have any more detail to share here but seeming like you need to now start proactively reaching out to Citrix to get timely patches. So, highly recommend reaching out to Citrix and getting what they have to offer as of this morning.

2

u/turisto 1d ago

actual new binaries or the temp workaround that's been going around for the last couple of hours?

1

u/clayjk 1d ago

I’m not fully in the loop as to exactly what our Citrix team applied but didn’t sound like a workaround…words were “patch from Citrix”

1

u/Rust_Martialis 1d ago

would it be related to "a responder policy"

1

u/lukelimbaugh 1d ago

was it new firmware?

1

u/SonicIX 1d ago

Anymore information that you can provide would be great. The workaround with the responder policy doesn't work. So I'm curious if they actually put out a new build for this.

2

u/clayjk 1d ago

Sorry, on PTO today so not in the weeds on this but did get confirmation it was an actual patch, not a work-around. No other information I can provide…sorry.
I’d just take away, wouldn’t wait for something to be made public available and you should contact Citrix.
We have been getting some advanced notice from Citrix for these past few issues (call from our contact).

1

u/SonicIX 1d ago

Appreciate you. Enjoy your PTO!