Citrix StoreFront

Cumulative Update 7 (CU7)

Release date: Aug 28, 2025

What’s new in 2203 LTSR CU7

This release contains fixes for StoreFront 2203 LTSR Cumulative Update 7 (CU7). The following issues have been reported since the CU6 release of the 2203 LTSR.

Citrix Workspace app for HTML5

This release includes Citrix Workspace app for HTML5 25.5.0.19.

Fixed issues in 2203 LTSR Cumulative Update 7 (CU7)

StoreFront 2203 LTSR CU7 contains all fixes included in CU6, and the following are the new fixes:

  • When enabling ICA signing using the PowerShell command Set-STFStoreService $storeService -IcaFileSigning $true, the command doesn’t set the necessary permissions on the certificate, causing ICA signing to fail. [CVADHELP-26649]

  • In the StoreFront customization API, users can include custom footers by inserting content into the element with the ID customBottom. However, there are two sections that contain elements with the same ID customBottom, which might result in unexpected behavior for customizations. [CVADHELP-26564]

  • Auto launch desktop does not work after one year following the first time the user accesses the website. [CVADHELP-26817]

  • A malformed URL might cause an Internal Server Error with a binary response body. [CVADHELP-26916]

  • When socket pooling is enabled, the Citrix Subscription Synchronization Service might show high memory usage on StoreFront servers or cause port exhaustion causing service unavailability. [CVADHELP-26838]

  • When HDX Direct is enabled, StoreFront includes unnecessary VDA host details in the ICA file when a client initiates an HDX connection through a gateway. [CVADHELP-27112]

  • The Content Security Policy defined in the http-equiv tag of the HTML file has been updated to block inline scripts. [CVADHELP-27487]

    Note:

    Customizations to StoreFront that use eval or insert inline scripts into the DOM will no longer function due to this update. [CVADHELP-27487]

  • When Cloud Connectors operate in LHC mode and a user attempts to launch a resource that is accessible from multiple locations, the session might fail to start if the resource isn’t immediately available.

    The issue occurs because, after checking the resource’s readiness, StoreFront might send the request to a different connector than the one initially used to launch the resource. [CTXENG-64445] [CVADHELP-28639]

Cumulative Update 7 (CU7)