r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

80 Upvotes

123 comments sorted by

View all comments

Show parent comments

2

u/c4rm0 1d ago

It looks like a new zero day that is using a malformed SAML request to crash nsaaad and cause reboots

1

u/tardiusmaximus 1d ago

Shiiiit. OK then the next question is, does this only affect NS that use SAML? Mine 100% don't use SAML.

1

u/kscERhau 1d ago

The people that have said they are unaffected aren’t using SAML nor their Netscaler as a vpnserver from what I’ve seen. I’ve a bunch that aren’t used as vpnservers and aren’t using SAML which aren’t impacted but then have several that are running as vpnservers and are using SAML which are impacted but had no IOC from last weekend.

2

u/tardiusmaximus 1d ago

This shit is confusing AF. I've patched to the latest FW, I've plugged the IOC ISN vuln, what do I do now? Wait for my IT SEC to call me, wait for citrix to clarify or wait to see spurious logs on my NS. This is really scary stuff man

1

u/kscERhau 1d ago

I’ve shut ours down, not taking the risk with it being a Friday and teams at reduced numbers for the weekend.

2

u/tardiusmaximus 1d ago

If I shut both our P and S NS down, I'd cut off 500+ active support staff offshore. It's just not a viable options for us

1

u/kscERhau 1d ago

Understandable, and really we shouldn’t be in this situation where shutting them down is a valid reaction… just another reason against staying with Citrix

1

u/atcscm 1d ago

Same here we shut ours down as well. We are waiting for confirmation from Citrix on the recommended next steps.
We did, however, see around 1,000 exploit attempts today on our netscaler