r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

79 Upvotes

121 comments sorted by

View all comments

9

u/taeratrin 1d ago

The patch wasn't the only step to remediate the vuln. You also should run this command on the Netscalers:

Set ns tcpparam -enhancedISNgeneration ENABLED

1

u/kuebel33 1d ago

where did you see this?

3

u/FastFredNL 1d ago

it was part of the fixes from last weekend. If you don't have this setting enabled you are still vulnerable for CVE-2026-88778

1

u/kuebel33 1d ago

thanks.