← Vulnerability feed

Vulnerability record · CVE-2025-7775 · published 26 August 2025

CVE-2025-7775: Citrix NetScaler memory overflow allows remote code execution

Citrix · Netscaler Application Delivery Controller

NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affects Gateway-configured deployments (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual servers, and specific load-balancing or CR virtual server configurations involving IPv6 services or HDX. Because these are edge appliances, a compromise exposes the network perimeter.

9.2 CVSS 4.0 Critical CISA KEV since 26 Aug 2025 EPSS 20% · top 2.7% CWE-119 · Memory buffer overflow
9.2CVSS 4.0 base score
20%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score 9.2, CISA KEV listing with a two-day remediation deadline, and a 97th percentile EPSS score indicate active exploitation of an internet-facing edge appliance.

What it is

NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affects Gateway-configured deployments (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual servers, and specific load-balancing or CR virtual server configurations involving IPv6 services or HDX. Because these are edge appliances, a compromise exposes the network perimeter.

Impact

A remote attacker can execute code on the appliance or crash it, gaining a foothold on an internet-facing system or disrupting access for all users.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), but exploitation requires specific conditions (AC:H, AT:P) and a vulnerable configuration such as a Gateway, AAA, or IPv6-bound load-balancing virtual server.

Exploitation

Listed in CISA KEV with a 2025-08-26 addition and a 2025-08-28 remediation due date, indicating known exploitation; EPSS 30-day probability is about 19.6 percent (97th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Citrix vendor update referenced in CTX694938 immediately; this is the primary fix.
  • If patching cannot be done at once, follow Citrix mitigation guidance or take the appliance out of service per CISA BOD 22-01.
  • Restrict management and VPN/AAA virtual server exposure to trusted networks where operationally possible.
  • Review configurations for the affected Gateway, AAA, IPv6-bound load-balancing, and HDX CR virtual server setups and disable unused ones.
  • Monitor Citrix and CISA advisories for updated guidance until fully remediated.

Detection

  • Review NetScaler and Citrix Gateway logs for crashes, unexpected restarts, or memory-related errors on affected virtual servers.
  • Hunt for unusual outbound connections, new processes, or file changes on NetScaler appliances that could indicate post-exploitation.
  • Alert on anomalous traffic to Gateway, AAA, or IPv6-bound load-balancing virtual servers from untrusted sources.
  • Correlate appliance logs with authentication and access logs to spot exploitation attempts or follow-on lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-7775 to the Known Exploited Vulnerabilities catalog on 26 August 2025 as "Citrix NetScaler Memory Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-7775 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed7.5CVE-2023-6549Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoSNetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2025-7775), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.