Citrix has issued a warning that recent security patches for critical vulnerabilities may cause login page failures on NetScaler ADC and Gateway appliances, creating an unexpected challenge for administrators.
## The Problem
The issue stems from NetScaler versions 14.1.47.46 and 13.1.59.19, where the Content Security Policy (CSP) header is now enabled by default. While CSP is designed to protect against cross-site scripting (XSS) and code injection attacks, it’s inadvertently blocking legitimate authentication scripts.
Organizations using DUO configurations with Radius authentication, custom SAML setups, or other Identity Provider (IDP) configurations may experience “broken” login pages after upgrading to these NetScaler builds.
## Critical Vulnerabilities Requiring Immediate Attention
Despite the login issues, Citrix emphasizes that administrators must immediately patch two critical security flaws:
– **CVE-2025-5777 (Citrix Bleed 2)**: Allows attackers to bypass authentication by hijacking user sessions
– **CVE-2025-6543**: Currently being exploited in denial-of-service attacks
## Temporary Solution
To address the login page issues while maintaining security patches, Citrix recommends:
1. **Disable the default CSP header** on affected NetScaler appliances through either the user interface or command line
2. **Clear the cache** to ensure changes take effect immediately
3. **Test the NetScaler Gateway authentication portal** to verify the issue is resolved
## Next Steps
If problems persist after following these steps, administrators should contact Citrix Support with detailed configuration information and the troubleshooting steps already taken. The company is working to identify and fix CSP-related issues for specific configurations.
This situation highlights the ongoing challenge of balancing security enhancements with system functionality, requiring careful coordination between security updates and operational requirements.
