Vulnerability record · CVE-2025-5777 · published 17 June 2025
CVE-2025-5777: Citrix NetScaler ADC/Gateway memory overread via insufficient input validation
Citrix · Netscaler Application Delivery Controller
CVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. It is tracked as CitrixBleed 2 and has been added to CISA KEV, with a CVSS 4.0 base score of 9.3 (critical).
Description
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 9.3, unauthenticated network reachability, CISA KEV listing with known ransomware use, and near-maximum EPSS probability make this an urgent patch-first issue.
What it is
CVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. It is tracked as CitrixBleed 2 and has been added to CISA KEV, with a CVSS 4.0 base score of 9.3 (critical).
Impact
An unauthenticated remote attacker can read memory contents from the appliance, which can expose session tokens and other sensitive data. Because the flaw is network-reachable and requires no privileges or user interaction, it can lead to credential/session theft and follow-on access to protected resources.
Attack surface
Reachable over the network via the NetScaler Gateway or AAA virtual server interfaces; the CVSS 4.0 vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. Only deployments configured as Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers are affected.
Exploitation
CISA added CVE-2025-5777 to KEV on 2025-07-10 with a due date of 2025-07-11 and flags known ransomware campaign use; EPSS 30-day probability is 0.99964 (99.975th percentile). Multiple third-party advisories and press coverage describe active exploitation.
What to do
- Apply the Citrix vendor security update referenced in CTX693420 immediately; this is the primary fix.
- If patching cannot be completed, follow Citrix mitigation guidance or discontinue use of the affected Gateway/AAA virtual server configuration.
- Rotate credentials and invalidate active sessions on affected appliances after patching, since memory disclosure can expose session tokens.
- Restrict network exposure of NetScaler Gateway/AAA virtual servers to trusted sources where operationally feasible.
- Monitor CISA KEV/BOD 22-01 guidance for cloud-hosted instances and apply the same remediation timeline.
Detection
- Review NetScaler ADC/Gateway logs for anomalous or malformed requests to Gateway/AAA virtual servers around the June 2025 onward exploitation window.
- Hunt for unexpected session token reuse or authentication from unusual source IPs against NetScaler-protected resources.
- Monitor for post-exploitation activity such as new administrative accounts, configuration changes, or outbound connections from the appliance.
- Correlate NetScaler appliance telemetry with EDR/network logs for memory-disclosure probing patterns described in public CitrixBleed 2 write-ups.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-5777 to the Known Exploited Vulnerabilities catalog on 10 July 2025 as "Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 11 July 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-5777 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-5777), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.