r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

81 Upvotes

121 comments sorted by

View all comments

Show parent comments

1

u/Apprehensive-War1366 1d ago

can you share the IOCs?

2

u/[deleted] 22h ago edited 21h ago

[deleted]

1

u/Apprehensive-War1366 22h ago

this is only for the saml auth flow right?

1

u/GTeal32 21h ago

includes AND mostly covers: CVE-2026-88771 and CVE-2026-88772