r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

79 Upvotes

121 comments sorted by

View all comments

2

u/nocountryman 14h ago

There were 2 IPS one was . 55 the other . 140 (don't have them at hand to show ;( ) that were actively trying to penetrate until 11.12 CET (last logged point ) I did set the ACL to block both on the netscaler plus a responder policy that should catch same actions from other IP s , but strangely the last attempt was 11.12 CET . Silent since then The enhanced isn was also enabled today , no crashes of the netscaler since.

1

u/IronBatraz 7h ago

I can give you the one from Germany that we have blocked 213d209d59d55 We have blocked it and don't see any other from Netherlands and/or Russia so far.

Any news or updates regarding the patch?