HomeSecurityCitrix: Connection issues after NetScaler update

Citrix: Connection issues after updating NetScaler

Citrix warns that applying fixes for the recently disclosed vulnerabilities, which can be exploited to bypass authentication and perform denial of service (DoS) attacks, may also cause connectivity issues on NetScaler ADC and Gateway.

See also: Citrix patches critical vulnerability in NetScaler Console and NetScaler Agent

Citrix connection problems

This is because, starting with NetScaler versions 14.1.47.46 and 13.1.59.1 9, the Content Security Policy (CSP) header is enabled by default , which reduces the risks of cross-site scripting (XSS) attacks, malicious code injection, and other client-side attacks.

However, while designed to block unauthorized scripts and external content from running in the browser, this policy inadvertently and legally restricts scripts or resources used in DUO over Radius configurations, integrations, custom SAML settings, or other identity provider (IDP) configurations that do not comply with the strict CSP rules.

See also: Citrix fixes serious vulnerability in NetScaler Console and NetScaler Agent

The first of the two security vulnerabilities (registered as CVE-2025-5777 and known as Citrix Bleed 2) allows malicious actors to bypass authentication by intercepting user sessions, while the second (CVE-2025-6543) is already actively used in denial-of-service (DoS) attacks.

NetScaler update

To temporarily address the connection issue, Citrix recommends that administrators disable the default CSP header on affected NetScaler appliances (via the UI or command line) and clear the cache so that the changes take effect immediately.

After disabling the CSP header, administrators are also advised to access the NetScaler Gateway authentication page to verify if the issue is resolved.

See also: Vulnerabilities in Citrix XenServer and Hypervisor allow Host collapse

Temporarily disabling the CSP header is a workaround to restore functionality (especially if there is a problem with authentication via DUO, SAML, etc.), but it should be applied with caution, as it reduces the browser's protection against XSS attacks. Ideally, more targeted CSP settings should be implemented that allow the required exceptions without completely removing the policy.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS