Citrix NetScaler users have encountered persistent reboot cycles following the installation of build 14.1-73.37. This update was urgently released to address two zero-day vulnerabilities that were actively being exploited.
Causes of Reboot Issues
The reboot problem seems to be associated with specific SAML authentication traffic, which disrupts the nsaaad service. Citrix has acknowledged a new SAML-related issue and is working on a revised security bulletin and an updated build to resolve this.
It’s crucial to note that these reboots do not imply that the vulnerabilities patched in September have been compromised. The build 14.1-73.37 remains the remedial version for the vulnerabilities CVE-2026-88771 and CVE-2026-88772.
Impact on Network Security
The first vulnerability allows unauthorized command execution on affected systems, while the second could enable code execution or denial of service if DTLS is active. Citrix has confirmed that systems not updated are at risk of exploitation.
Administrators have reported on platforms like Reddit that NetScaler appliances on build 14.1-73.37 have spontaneously entered reboot loops, affecting multiple customers and resulting in high-priority cases with Citrix.
Guidance for IT Administrators
Administrators are advised to maintain core files, system logs, authentication records, and support bundles to avoid losing critical data during reboots. It is recommended to match reboot timing with SAML request logs, firewall entries, and identity provider records.
Organizations should verify the version of the build on both active and standby nodes. Citrix bulletin CTX697096 confirms 14.1-73.37, alongside other releases, as the solution to the zero-day vulnerabilities.
Despite the patch, it’s possible for previously exploited access points, such as web shells, to remain, emphasizing the necessity for continued vigilance. Until further updates are provided, users should adhere to vendor mitigation strategies and treat unexplained reboots as potential security events.
