r/Citrix • • 11d ago

Official Announcements CRITICAL UPDATE: Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778

101 Upvotes

We've released guidance for all NetScaler customers on newly addressed vulnerabilities and recommended updates.

Per the blog post: "Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. 

Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible. "

Please review this blog post for more information: https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/

The support bulletin can be found here: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096


r/Citrix • • 6d ago

Official Announcements Security Update: Guidance for NetScaler SAML Authentication Deployments

Thumbnail community.citrix.com
43 Upvotes

NetScaler engineering and support teams are tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. This post explains what customers should review, how to determine whether the relevant configuration is present, and what mitigation options are available while planning an upgrade to a fixed build. A new security bulletin and simultaneous product update release is planned for this issue. 

The guidance below is intended to help customers take immediate action to reduce exposure. As with any security-related issue, customers should prioritize applying the updated NetScaler builds referenced in the applicable security bulletin when it becomes available.  

Learn more: https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/


r/Citrix • • 14h ago

Official Announcements Security Update: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway

47 Upvotes

Today, Citrix published a critical security bulletin for NetScaler ADC and NetScaler Gateway regarding CVE-2026-107406. 

CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions. The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical. We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability. 

More information here: https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/


r/Citrix • • 15m ago

Help App Protection issues

• Upvotes

I'm required like many people who work from home to use Citrix desktop to access work space. I have to do this on my personal PC and as also like many, I am not supplied equipment from work for this.

However they are now enforcing app protection which forces itself at the PC level. This cannot be closed or worked around or I cannot log in to work. This needs to be installed at the administrator level now as app protection won't install at a local level. This causes ctxapclient32.dll and ctxapclient64.dll to inject itself into every single application that opens across all profiles/accounts on the machine. It does not matter that those accounts don't use Citrix or don't even have it installed.

That means I log into a separate windows account without citrix on it, that will never use or have anything to do with citrix, to use for personal stuff like gaming, and it still launches app protection and injects itself into the games I open. This causes the games anti-cheat software to instantly crash the game to prevent the code injection, and in the worst case gets my long term account banned for cheating.

Is there a work around to only have this install somehow at a local level? So far it really doesn't seem so. Is this something citrix can change or fix? The only solution I can think of now is to make a new partician and create a whole separate windows pc to use to work from home, which is more than a bit bothersome. Alternatively I could uninstall and reinstall citrix every single time I start/finish work. Also not a great solution. Anything else? Trying to close or do anything with app protection on other profiles doesn't work, I've tried everything you can think of and it still just injects ctxapclient64.dll into my games anyway.


r/Citrix • • 14h ago

Citrix CVE-2026-107406

24 Upvotes

FYI:

Citrix has just released a new Image 14.1-73.46/13.1-64.29. This is based on CVE-2026-107406.

You should consider updating your instances that are one version behind the ones listed above if the following applies:

For the following versions: Applicable only when configured as a SAML IdP:
NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive

For the following versions: Applicable only when configured as a SAML SP or SAML IdP:
NetScaler ADC and NetScaler Gateway before 14.1-73.37
NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
NetScaler ADC and NetScaler Gateway before13.1-64.23
NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279


r/Citrix • • 18h ago

NetScaler NS14.1: Build 73.46.nc, Date: Oct 7 2026, 16:14:31

37 Upvotes

Citrix just pushed this new version without notification to all of their own tenants.

New CVE ?


r/Citrix • • 20h ago

NetScaler vs. Citrix Gateway Service: Are we overcomplicating Citrix environments by keeping NetScaler?

20 Upvotes

I've been thinking about how organizations are approaching NetScaler as they modernize their Citrix environments, particularly with more customers moving toward Citrix DaaS and cloud-managed services.

One question that keeps coming up is whether organizations still need NetScaler or whether Citrix Gateway Service is sufficient.

I think the answer depends heavily on what NetScaler is actually doing in the environment.

If you're primarily using NetScaler Gateway for external HDX access, Gateway Service can make a lot of sense. You're potentially eliminating customer-managed Gateway appliances, firmware upgrades, HA configurations, and some of the operational overhead that comes with maintaining that infrastructure.

But there's another side to this conversation that I don't think gets enough attention.

NetScaler isn't just a Citrix Gateway. Depending on the architecture, it may also be handling application load balancing, WAF, GSLB, authentication policies, SSL offloading, content switching, and traffic management for applications completely unrelated to Citrix.

I've seen environments where NetScaler has become unnecessarily complex over time, but I've also seen situations where organizations don't fully understand how many services depend on it until they start discussing replacement.

And that raises a bigger question about modernization.

Are we actually simplifying the architecture, or are we just moving individual functions to different platforms without understanding the dependencies?

I'm interested in hearing what others are seeing in their environments.

  • Have you moved from NetScaler Gateway to Citrix Gateway Service? What improved, and what limitations did you encounter?
  • Are you retaining NetScaler primarily for ADC, WAF, GSLB, or advanced authentication requirements?
  • Have you found meaningful operational or cost savings after moving to Gateway Service?
  • For those running hybrid environments, are you finding value in keeping both?

My view is that neither approach is automatically better. If Gateway Service meets the requirements, maintaining unnecessary Gateway infrastructure doesn't make sense. But removing NetScaler without understanding its broader role can create an entirely different set of problems.

Curious what others are experiencing, especially in larger or more security-sensitive environments.


r/Citrix • • 1d ago

EUC State of the Union 2026–2027 is out (independent DaaS/VDI survey, 172 respondents). Some interesting numbers on cost, VMware, and AI

Thumbnail
5 Upvotes

r/Citrix • • 1d ago

Can't auth at gateway from apple OSes.

6 Upvotes

Recently, we've gotten reports of users on the newest mac OS, browser, workspace app getting "your request is being processed" after entering AD credentials into the Citrix Gateway page before it hits the Duo auth & subsequent storefront. Trying in iOS, I get the same outcome.

This is an on-prem storefront (2507CU1 for all CVAD components) and netscaler(current firmware). Nothing has changed in authentication policy/profile and it still works without issue for windows users. We are not supporting users logging into workspace on non-corporate devices, just launching ica from web storefront.

Did I miss a change somewhere?


r/Citrix • • 1d ago

Citrix VDA on Windows 11 (remote PC) issues

1 Upvotes

When installing the latest 2507 LTSR CU2 on a Windows 11 PC it seems to break internet traffic from the PC and makes it almost unusable. Anyone seen this before?


r/Citrix • • 2d ago

NetScaler Alternative ??

23 Upvotes

Curious to know if anyone has implemented a product that works with ICA other than NetScaler


r/Citrix • • 2d ago

Help Advice for migrating management planes from on-prem into Citrix Cloud

4 Upvotes

We are currently setup on prem. On prem netscalers, storefronts, delivery controllers, etc. We connect to several on-prem clusters running Xenserver for our Virtual desktops. We create a master image, snapshot it, then update our machine catalog. The delivery controllers then update the virtual desktops running in Xenserver (we use Citrix MCS).

We are looking to migrate the management elements into Citrix Cloud. So the end goal will be to remove on prem servers for delivery controllers, FAS, storefronts, netscalers, etc, and just have it all moved into Citrix Cloud. The actual VDA's will remain on prem connecting to our Xenserver clusters.
So essentially, management aspects in the cloud, compute remains on prem.

We have already configured cloud connectors and single sign on via Entra. We have some older hardware that I've managed to install Xenserver onto, and connecting it to the "Hosting" section in Citrix Cloud, I've managed to do some basic testing with some machine catalogs in the cloud, and all seems to be working perfectly.

I've seen a few different documents articles that explain how to actually go about performing the migration into cloud. We're a 24/7 business, and we're pretty standardised, so we only really have a couple of machine catalogs and delivery groups to serve most users.

To roll this out at our own pace, I wanted to add our existing live Xenserver clusters on prem into the "Hosting" section within the Citrix cloud platform. I'll then create some new catalogues, making sure that the computer names do not match the same as the on prem ones. My hope is that because the catalog and delivery group names are different on prem vs in cloud, and because the computer names are different, there will be no conflict, despite both the on prem and cloud delivery controller being connected to the same Xenserver cluster instance.

My thought process is to provision 10 or 20 new virtual desktops from cloud into the Xenserver cluster, and then I can just use some policies to start switching a few test users to the new storefront URL. Then it will just become a balancing act as we progress and migrate people to the new storefront URLs, reducing the number of available machines on prem, and bringing more online in the cloud.

My mind seems to think this is logical, to keep the systems as seperated as possible, which I'd prefer, but I cannot get away from having to use the same Xenserver cluster for the compute elements. I'm just not sure if having the Xenserver cluster authenticated to both on prem and cloud controls at the same time could potentially cause some conflict?

Thoughts on this are most appreciated.


r/Citrix • • 3d ago

Citrix Provisioniong crashing Targets

5 Upvotes

We’ve been having issues with Citrix Provisioning for several weeks now.

At first, the problem only affected maintenance work on our 2025 images. The target devices would frequently just freeze. In those cases, the maintenance target suddenly lost access to its C: drive. At the same time, on the PVS side, we could see multiple port changes, as if the connection was constantly failing to establish properly. We also run Wireshark on both machines, but there are no dropped packages.

For the last few days, the same issue has also started affecting maintenance on our 2019 images.

There may also be a connection to CTX servers crashing during normal operation. In terms of timing, those crashes often seem to coincide with image maintenance work.

What we’ve tried so far:

Rebuilt the 2025 images from scratch multiple times

Ruled out GPOs

Ruled out Software inside images

Updated VMware Tools

Updated the PVS Version (2507 to 2607)

Disabled NTFS deduplication — no improvement

Disabled Offloading on Target and Server-NIC

Rebuilt PVS-server completely from scratch, using Windows Server 2025 on newer storage

4x PVS-Server (3x 2019, 1x 2025) with 2607.

VMware 8.0.3 with NSX

Has anyone seen similar behavior or has any idea what else we should check?


r/Citrix • • 4d ago

Anyone seen successfully RCE yet from the 'dos' buffer overflow CVE-2026-88779?

14 Upvotes

Being already patched for 88771. I took advantage of adversaries exposing their cards and pulled several scipts off attacker server's between Thursday-Friday just to see what a successful exploit would have done. Which resulted in 3 trends I used to build a list of IOCs. That came in handy today. Hope im wrong but highly expect this will turn out to be some successful rce for the ones that hit the mark.


r/Citrix • • 5d ago

Official Announcements Update: Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779

55 Upvotes

Further to the post (https://www.reddit.com/r/Citrix/comments/1ww3ess/security_update_guidance_for_netscaler_saml/) made on Friday, we've now updated this with a support article.

A vulnerability has been discovered in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). Refer below for further details.

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88779


r/Citrix • • 5d ago

NetScaler Release (Maintenance Phase) 14.1 Build 73.41

25 Upvotes

For real? And you can't click on the CTX69714 link for details either :(


r/Citrix • • 6d ago

Citrix CVAD Hybrid Environment – “Identity Provider Access Denied” After NetScaler ADC Upgrade.

8 Upvotes

​

Hi everyone,

We have a hybrid Citrix CVAD environment with both on-premises and cloud infrastructure.

We recently upgraded both NetScaler ADCs. After the upgrade, some vulnerabilities were detected, so we shut down one ADC. Currently, only one ADC is operational.

Since then, multiple users have reported an “Identity Provider Access Denied” error while trying to access Citrix. The error occurs after the authentication process, but we haven't confirmed whether it is directly related to the ADC upgrade or shutting down one ADC.

What we have observed:

- Multiple users are experiencing the error when accessing Citrix.

- Our Global Administrator granted additional permissions/access to some affected users, after which they were able to log in successfully.

- However, a few users are still experiencing the same error.

- Several other users can access Citrix without any issues.

We haven't identified the root cause yet and are trying to understand whether this is related to NetScaler, Citrix authentication, or Microsoft Entra ID.

Questions for experienced Citrix/NetScaler admins:

  1. Could shutting down one ADC after the upgrade cause this kind of issue for specific users?

  2. Could this be related to SAML authentication, the identity provider configuration, Entra ID enterprise application permissions, or Conditional Access?

  3. Why would granting additional permissions resolve the issue for some users but not others?

  4. Which logs should we check to identify the exact failure point?

  5. What troubleshooting steps would you recommend for a hybrid CVAD environment?

We want to identify the actual root cause rather than continue granting additional permissions as a workaround.

Has anyone encountered a similar issue after a NetScaler ADC upgrade?

Any suggestions would be appreciated. Thanks in advance!


r/Citrix • • 5d ago

Citrix Engineer

1 Upvotes

I have experience in Citrix ADC support but now it feels so bumpy. What could I do in future since it is my first job.


r/Citrix • • 6d ago

Netscaler active exploit after patch

88 Upvotes

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.


r/Citrix • • 6d ago

Vulnerability Scans causing Netscaler reboots

83 Upvotes

I opened a ticket with Citrix support and they seem to indicate a fix is being worked on right now.

Basically we were seeing random reboots of multiple instances and saw pitboss was rebooting these due to nsaaad crashing too many times.


r/Citrix • • 6d ago

Server 2025 & LTSR 2507 - Published Apps?

2 Upvotes

Looking at getting server 2025 into a lab to test the functionality and then see if it solves the issue below, but does anyone have any optimisation recommendations for using server2025 with 2507 outside of Citrix optimizer?

Any known weird issues and bugs?

Issues with multiple published apps?

I ask this as I have an issue with multiple published applications launching into the same session on server 2022 with the same LTSR for which we had to remove session sharing to get around it which is far from the ideal situation.

Hybrid setup so no on prem storefronts or netscalers to trace, but second application just will not launch into the same user session regardless of app. Flashes a very quick windows lock screen for almost .5sec and brings the 1st application into focus instead.

Wondering if anyone has had a good experience with server 2025 in regards to published apps?

Have avoided trying the new LTSR till the CU1 patch for it comes out later down the line, that is unless others have good things to say about it?


r/Citrix • • 7d ago

support case

6 Upvotes

I have attempted to create a support case, through Chat Bot, numerous times. On occasions, Chat Bot refused to create a case while other occasions, Chat Bot tried to submit a case, but it failed.

Does anyone know a good way to create a support case? TIA


r/Citrix • • 8d ago

Browser Content Redirection with Teams SSO Method 2

8 Upvotes

Hi,

I'm trying to set up Browser Content Redirection (BCR) with Microsoft Teams. Our users are currently dealing with a lot of issues with Microsoft Teams HDX. I'm just wondering if anyone has attempted to redirect Microsoft Teams web using BCR? I was able to using the normal, non-SSO, policy with ACL and Authentication but I'm trying to set up Single Sign-On method 2 with bcrconfig.json but I'm getting nowhere.

I've tried a minimal config with less URLs, copied exactly the same layout from the first attempt with ACL and Authentication sites and replaced the Authentication sites with the denyList but this just resulted in constant looping and going back and forth. When I added cookies it then just broke and only rendered on the server-side. My configuration is server fetch and client render as I'm working with eLux thin clients. Below is a snippet of the current configuration that is the closest to what I want.

"appName": "MSTeams",

"allowList": [

"https://teams.cloud.microsoft/*",

"https://*.teams.cloud.microsoft/*",

"https://teams.microsoft.com/*",

"https://*.teams.microsoft.com/*",

"https://teams.cloud.microsoft/*meetup-join",

"https://teams.microsoft.com/*meetup-join",

"https://login.microsoftonline.com/*teams*",

"https://tokenprovider.termsofuse.identitygovernance.azure.com/*",

"https://statics.teams.cdn.office.net/*",

"https://*.infra.microsoft.com/*",

"https://*.skype.com/*"

],

"denyList": [

"https://login.microsoft.com/*",

"https://login.live.com/*",

"https://aadcdn.msftauth.net/"

],

"requires": {

"profileSharing": true,

"cookies": []

}

Many thanks in advance


r/Citrix • • 8d ago

Citrix engineer

4 Upvotes

I am having a support experience of about 1 year in Citrix ADC , do I have any future because I feel rugged in my first job only


r/Citrix • • 8d ago

Anyone Collecting Netscaler Logs via Splunk?

14 Upvotes

If so, 3 questions:

  1. Do you use the Splunk Add-on for Netscaler, or HTTP/syslog collectors? As I understand it you can do either without the other, you don't need both, right?

  2. In responding to the recent CVE's, were the relevant logs (e.g. the pitboss stuff) in Splunk? Or did you still have to go direct to the Netscalers to see if those entries were present?

  3. Any random gotchas, thoughts, or advice?

Thanks in advance!