A little over a week after issuing patches for critical NetScaler flaws, Citrix is warning that the fixes may break login functionality for some users.
First reported by BleepingComputer, the issues stem from changes introduced in NetScaler builds 14.1.47.46 and 13.1.59.19, which sought to address two high-severity vulnerabilities: a denial-of-service (DoS) bug (CVE-2025-6543) and an authentication bypass flaw (CVE-2025-5777), also known as CitrixBleed 2.
The flaws, affecting Citrix’s NetScaler Application Delivery Controller (ADC) and Gateway platforms, emerged just last week and were reportedly exploited in the wild before patches were available.
Now, Citrix has followed up with an advisory warning that the latest fixes may disrupt legitimate authentication processes, especially in environments using third-party identity providers or custom login scripts.
The root cause is a newly-enabled Content Security Policy (CSP) header, introduced by default as part of Citrix’s secure by design initiative.
While CSP is designed to block unauthorized scripts and mitigate risks like cross-site scripting (XSS), the vendor said the fix can inadvertently block legitimate scripts.
“This can manifest as a ‘broken’ login page, especially when using authentication methods like DUO configurations based on Radius authentication, SAML, or any Identity Provider (IDP) that relies on custom scripts,” Citrix explained in its latest bulletin.
As a temporary workaround, Citrix recommends disabling the CSP header if authentication portals are impacted and clearing browser caches to ensure the changes take effect.
Users are also encouraged to validate whether the patch was successfully applied without breaking access for users.
For enterprises with more complex identity ecosystems or remote access dependencies, the fix-for-the-fix may, however, add an unplanned layer of operational overhead, particularly for those under pressure to remediate CitrixBleed 2 before it can be exploited further.
“If the issue persists after following these steps, please reach out to Citrix Support for further assistance,” the advisory recommends. “Provide them with details of your configuration and the steps you have already taken.”
The initial CitrixBleed flaw caused widespread ransomware attacks in late 2024, prompting cybersecurity expert Kevin Beaumont to observe that threat actors were “collecting session tokens like Pokémon.”
Comments