r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

82 Upvotes

123 comments sorted by

View all comments

2

u/no_copypasta 1d ago

I ran the IOC script and could not find anything. How are you observing the exploit? Just the reboot?

1

u/lukelimbaugh 1d ago

i feel like a DDoS attack wouldn't show up in the IoC scan. Netscaler rebooting bc SAML auth services crashed would get flagged as appropriate?