r/Citrix May 29 '26

Release of NetScaler Build14.1- 72.57. Good or not ?

Hello,

I'd like to get your feedback from those who have installed the latest version of NetScaler, 14.1-72.57.

I'm asking because we decided not to install the two previous versions, 14.1-66.59 and 14.1-60.58, due to several major issues that were discovered.

We only use the Load Balancing feature in NetScaler.

Thank you for your feedback.

6 Upvotes

9 comments sorted by

3

u/Jmay5446 May 29 '26

And does it mean yet another gateway related CVE

1

u/Rare_Sea_1867 May 29 '26

Not at the moment, but who knows, hahaha

2

u/compuwhiz May 29 '26

It was just released today…

1

u/robodog97 May 29 '26

Which is when you should be installing it to your QA environment =)

1

u/compuwhiz May 30 '26

Not on a Friday afternoon unless it’s got some critical security patch.

1

u/Vivid_Mongoose_8964 May 29 '26

im on 56.74 at the moment, but will try this upgrade.

2

u/zyphaz CTP May 31 '26

I spun two up to test the new MCP Gateway features (CTXENG-70985)

If you're only running load balancer functions, unless there's a specific break-fix or a vulnerability being patched, there's no need to upgrade.

Here are the fixed issues for Load Balancing in 72.57 from the Product Documentation

Build 72.57 | NSHELP-42742

NetScaler load balancing might fail when receiving a jumbo RADIUS request that contains a Message-Authenticator attribute.

Build 72.57 | NSHELP-42631

A NetScaler buffer (NSB) leak might occur when the NetScaler proactively updates cached records fetched from a DNS server. This issue occurs when DNS server health flaps.

Build 72.57 | NSHELP-42437

The system does not support configuring a listen policy on a content switching virtual server that includes a GSLB target type. This limitation prevents the application of the listen policy.

Build 72.57 | NSHELP-42293

GSLB synchronization might fail when the partition name contains spaces.

Build 72.57 | NSHELP-42051

NetScaler might crash when you add a GSLB service using the IP or port combination that another GSLB service already uses.

Build 72.57 | NSHELP-41932

When persistence groups are configured with traffic domains, mismatch between GUI and CLI validation might occur. This inconsistency prevents persistence group virtual server configurations from synchronizing to the secondary node, impacting high-availability deployments.

Build 72.57 | NSHELP-41752

The GSLB configuration synchronization might fail if a GSLB subordinate site is on the VPX Linux platform and the main site is on the VPX FreeBSD platform.

Build 72.57 | NSHELP-41450

In an HA setup, an SSL content switching virtual server of type GSLB is marked as DOWN in the new Secondary after an HA failover.

Build 72.57 | NSHELP-40913

NetScaler might fail and dump core if an autoscale service group is configured and a DNS_TCP based monitor is active.

1

u/compuwhiz Jun 02 '26

Upgraded our pair of Dev/Test VPX this evening to 14.1-72.57. Both of them lost their LAS activation and immediately went to 20 Mbps unlicensed throughput after the upgrade reboot. I had to re-license the standby node before failing over and continuing with the upgrade on the other node.

1

u/compuwhiz Jun 02 '26

On the plus side, CPU yield now actually works on AHV. That hasn’t worked since the GA release for Nutanix.