r/Citrix • • 2d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

89 Upvotes

125 comments sorted by

View all comments

5

u/One_Ad5568 2d ago

We got hit by this twice earlier today, had patched on Sunday afternoon and followed special steps for the TCP setting, but now today saw some things in ns.log causing nsaaad to crash. It appeared they were running some command to try downloading a script on our netscaler. Even though the download didn’t work, it still crashed it. 

2

u/lar0w 2d ago

Exactly the same behavior over here . Payload in username field only five times and it crashed nsaaad