Vulnerability record · CVE-2025-7775 · published 26 August 2025
CVE-2025-7775: Citrix NetScaler memory overflow allows remote code execution
Citrix · Netscaler Application Delivery Controller
NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affects Gateway-configured deployments (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual servers, and specific load-balancing or CR virtual server configurations involving IPv6 services or HDX. Because these are edge appliances, a compromise exposes the network perimeter.
Description
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score 9.2, CISA KEV listing with a two-day remediation deadline, and a 97th percentile EPSS score indicate active exploitation of an internet-facing edge appliance.
What it is
NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affects Gateway-configured deployments (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual servers, and specific load-balancing or CR virtual server configurations involving IPv6 services or HDX. Because these are edge appliances, a compromise exposes the network perimeter.
Impact
A remote attacker can execute code on the appliance or crash it, gaining a foothold on an internet-facing system or disrupting access for all users.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), but exploitation requires specific conditions (AC:H, AT:P) and a vulnerable configuration such as a Gateway, AAA, or IPv6-bound load-balancing virtual server.
Exploitation
Listed in CISA KEV with a 2025-08-26 addition and a 2025-08-28 remediation due date, indicating known exploitation; EPSS 30-day probability is about 19.6 percent (97th percentile). No ransomware campaign use is documented.
What to do
- Apply the Citrix vendor update referenced in CTX694938 immediately; this is the primary fix.
- If patching cannot be done at once, follow Citrix mitigation guidance or take the appliance out of service per CISA BOD 22-01.
- Restrict management and VPN/AAA virtual server exposure to trusted networks where operationally possible.
- Review configurations for the affected Gateway, AAA, IPv6-bound load-balancing, and HDX CR virtual server setups and disable unused ones.
- Monitor Citrix and CISA advisories for updated guidance until fully remediated.
Detection
- Review NetScaler and Citrix Gateway logs for crashes, unexpected restarts, or memory-related errors on affected virtual servers.
- Hunt for unusual outbound connections, new processes, or file changes on NetScaler appliances that could indicate post-exploitation.
- Alert on anomalous traffic to Gateway, AAA, or IPv6-bound load-balancing virtual servers from untrusted sources.
- Correlate appliance logs with authentication and access logs to spot exploitation attempts or follow-on lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-7775 to the Known Exploited Vulnerabilities catalog on 26 August 2025 as "Citrix NetScaler Memory Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 August 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-7775 | US Government Resource |
Track CVE-2025-7775 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-7775), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.