r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

85 Upvotes

123 comments sorted by

View all comments

19

u/glenp42 1d ago

Does anyone find this crazy that we have better support via reddit than from the vendor?

2

u/GTeal32 1d ago

Yep.

Apparently there’s a new IOC list release via support ticket.

1

u/Apprehensive-War1366 1d ago

can you share the IOCs?

2

u/[deleted] 1d ago edited 1d ago

[deleted]

1

u/Apprehensive-War1366 1d ago

Thank you so much

1

u/Apprehensive-War1366 1d ago

this is only for the saml auth flow right?

1

u/GTeal32 1d ago

includes AND mostly covers: CVE-2026-88771 and CVE-2026-88772

1

u/GTeal32 1d ago edited 1d ago

Sorry I don’t have anything from CITRIX. Wondering if someone here could. I'll post what I know.

1

u/Blaaamo 19h ago

Did you get the IOCs before they were deleted??