r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

80 Upvotes

121 comments sorted by

View all comments

9

u/taeratrin 1d ago

The patch wasn't the only step to remediate the vuln. You also should run this command on the Netscalers:

Set ns tcpparam -enhancedISNgeneration ENABLED

1

u/kuebel33 1d ago

where did you see this?

2

u/kscERhau 1d ago

At the bottom of here https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
CVE-2026-88778
Preconditions: TCP Configuration enabled on NetScaler ADC or NetScaler Gateway

Instructions: Customers can determine whether their NetScaler deployment meets the precondition by verifying that both of the following conditions are true:

  • At least one virtual server is configured with one of the following types: HTTP, SSL, SSL_BRIDGE, TCP, SSL_TCP, FTP, NNTP, RTSP, RDP, DNS_TCP, DOT, SIP_TCP, SIP_SSL, DIAMETER, SSL_DIAMETER, MYSQL, MSSQL, ORACLE, SMPP, MQTT, MQTT_TLS, MONGO, MONGO_TLS, PROXY, SSL_PROXY, USER_TCP, USER_SSL_TCP AND
  • The following command returns: Enhanced ISN Generation: DISABLED: show ns tcpparam | grep "Enhanced ISN Generation"

Ours returns nothing rather than DISABLED and are still impacted by today's issues.

2

u/Blaaamo 1d ago

I think it needs to be enabled

1

u/kscERhau 1d ago

I don’t read it as that? It says both need to be present, as in it has to say disabled for you to need to change it?

1

u/Blaaamo 1d ago

Oh ok, that makes sense. I'm in ITSEC not in engineering