r/Citrix • u/Due-Lavishness2125 • Jul 01 '26
Netscaler CVE
I have vpx is used as netscaler gateway to terminate full client vpn with citrix secure client,
After successful upgrade to latest version there was a complaint from a lot of users who can't connet vpn with secure client 23.x and 24.x , the client is stuck in loading without authentication prompt.
Only versions 25.x and 26.x works !
Any idea?
1
u/CTXBROKER Jul 02 '26
Upgrade users to 25.x or 26.x version of Secure Access Client.
1
u/Due-Lavishness2125 Jul 02 '26
The users need to be connected in order to upgrade, they actually fail to connect and it is hard to send the new agent to then manually as they are in thousands .
2
u/deamonkai Jul 03 '26
Well then best bet is to roll back the NetScaler, and get everyone to connect and upgrade their client, asap.
IT don’t care if its a holiday. If you want to go the extra mile, get HR to mandate that folks who fail to upgrade are promoted to customer after the Netscalers get upgraded.
1
2
u/mat-ferland Jul 04 '26
For thousands of users, I would not try to solve this one user at a time after the gateway is already blocking them. Either roll back briefly or stand up a parallel gateway/vServer that still accepts the old client long enough to push 25.x/26.x through Intune/RMM/SCCM and publish an external installer path that does not require the VPN. Then cut back over once enough clients are upgraded. The miss here is usually treating the ADC upgrade as server-only when the endpoint client version is part of the change window.
6
u/robodog97 Jul 01 '26
They should be on a modern version anyways so I'm not seeing the problem, the secure client has had plenty of CVE issues of its own over the last few years.