← Vulnerability feed

Vulnerability record · CVE-2025-5777 · published 17 June 2025

CVE-2025-5777: Citrix NetScaler ADC/Gateway memory overread via insufficient input validation

Citrix · Netscaler Application Delivery Controller

CVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. It is tracked as CitrixBleed 2 and has been added to CISA KEV, with a CVSS 4.0 base score of 9.3 (critical).

9.3 CVSS 4.0 Critical CISA KEV since 10 Jul 2025 Known ransomware use EPSS 100% · top 0.1% CWE-125 · Out-of-bounds readCWE-908 · Use of uninitialized resource
9.3CVSS 4.0 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
10References
4 Aug 2026Last modified by NVD

Description

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.3, unauthenticated network reachability, CISA KEV listing with known ransomware use, and near-maximum EPSS probability make this an urgent patch-first issue.

What it is

CVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. It is tracked as CitrixBleed 2 and has been added to CISA KEV, with a CVSS 4.0 base score of 9.3 (critical).

Impact

An unauthenticated remote attacker can read memory contents from the appliance, which can expose session tokens and other sensitive data. Because the flaw is network-reachable and requires no privileges or user interaction, it can lead to credential/session theft and follow-on access to protected resources.

Attack surface

Reachable over the network via the NetScaler Gateway or AAA virtual server interfaces; the CVSS 4.0 vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. Only deployments configured as Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers are affected.

Exploitation

CISA added CVE-2025-5777 to KEV on 2025-07-10 with a due date of 2025-07-11 and flags known ransomware campaign use; EPSS 30-day probability is 0.99964 (99.975th percentile). Multiple third-party advisories and press coverage describe active exploitation.

What to do

  • Apply the Citrix vendor security update referenced in CTX693420 immediately; this is the primary fix.
  • If patching cannot be completed, follow Citrix mitigation guidance or discontinue use of the affected Gateway/AAA virtual server configuration.
  • Rotate credentials and invalidate active sessions on affected appliances after patching, since memory disclosure can expose session tokens.
  • Restrict network exposure of NetScaler Gateway/AAA virtual servers to trusted sources where operationally feasible.
  • Monitor CISA KEV/BOD 22-01 guidance for cloud-hosted instances and apply the same remediation timeline.

Detection

  • Review NetScaler ADC/Gateway logs for anomalous or malformed requests to Gateway/AAA virtual servers around the June 2025 onward exploitation window.
  • Hunt for unexpected session token reuse or authentication from unusual source IPs against NetScaler-protected resources.
  • Monitor for post-exploitation activity such as new administrative accounts, configuration changes, or outbound connections from the appliance.
  • Correlate NetScaler appliance telemetry with EDR/network logs for memory-disclosure probing patterns described in public CitrixBleed 2 write-ups.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-5777 to the Known Exploited Vulnerabilities catalog on 10 July 2025 as "Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 11 July 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-5777 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed7.5CVE-2023-6549Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoSNetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2025-5777), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.