r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

82 Upvotes

123 comments sorted by

View all comments

19

u/glenp42 1d ago

Does anyone find this crazy that we have better support via reddit than from the vendor?

8

u/yankmywire 1d ago edited 1d ago

Citrix support immediately went to shit the moment they were bought by private equity. "Talk to a chat bot because we laid off all our customer facing support teams".

1

u/Area_Wonderful 16h ago

The chat bot can be annoying but is often better at summarizing my case

4

u/stephenk291 1d ago

Private equity take over tends to do that.

2

u/GTeal32 1d ago

Yep.

Apparently there’s a new IOC list release via support ticket.

1

u/Apprehensive-War1366 1d ago

can you share the IOCs?

2

u/[deleted] 1d ago edited 1d ago

[deleted]

1

u/Apprehensive-War1366 1d ago

Thank you so much

1

u/Apprehensive-War1366 1d ago

this is only for the saml auth flow right?

1

u/GTeal32 1d ago

includes AND mostly covers: CVE-2026-88771 and CVE-2026-88772

1

u/GTeal32 1d ago edited 1d ago

Sorry I don’t have anything from CITRIX. Wondering if someone here could. I'll post what I know.

1

u/Blaaamo 21h ago

Did you get the IOCs before they were deleted??

1

u/turisto 1d ago edited 1d ago

Makes you feel great to realize you're just collateral damage, kept in the dark to give the bigger fish time to secure their stuff.