ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Citrix Patches Three Zero Days as One Sees Active Exploitation

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-6543
Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild

Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known.

Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading.

9.210% KEV
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
large≈50,000+ internet-exposed NetScaler ADC/Gateway devices (only Gateway/AAA configurations vulnerable)
CVE-2025-7775
Actively Exploited Memory Overflow RCE/DoS in Citrix NetScaler ADC/Gateway

CVE-2025-7775 is a memory overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution and/or denial of service. It is triggered when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual server, or — on 13.1, 14.1, 13.1-FIPS, and NDcPP builds — when load-balancing virtual servers of type HTTP, SSL, or HTTP_QUIC are bound with IPv6 services or servicegroups with IPv6 servers (including DBS IPv6), or a CR virtual server of type HDX is in use. A remote, unauthenticated attacker (CVSS 4.0 network vector with no privileges required) who triggers the memory overflow can execute code with high impact on confidentiality and integrity or crash the device. Organizations running NetScaler in these exposed configurations, notably as remote-access gateways, are affected. Exploitation is confirmed in the wild: Citrix has confirmed active exploitation, the flaw was added to CISA's KEV catalog on 2025-08-26, and EPSS estimates a 19.6% probability of exploitation within 30 days (97th percentile).

Do: Upgrade all NetScaler ADC and Gateway appliances to the patched builds on the 13.1, 14.1, 13.1-FIPS, and NDcPP release trains identified in Citrix's security bulletin, prioritizing internet-facing devices. Audit configurations for Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual servers, HTTP/SSL/HTTP_QUIC LB virtual servers with IPv6 bindings, and CR virtual servers of type HDX to confirm exposure. The KEV listing makes applying vendor mitigations or the upgrade mandatory for US federal agencies under BOD 22-01.

9.220% KEV
  • Citrix NetScaler ADC 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; or with
  • Citrix NetScaler Gateway 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
large≈28,000+ internet-exposed NetScaler instances per public scans; total vulnerable deployments likely higher
CVE-2025-7776
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is conf

Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it

NVD description · AI analysis pending
8.87%
  • citrix netscaler application delivery controller
  • citrix netscaler gateway
CVE-2025-8424
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Clus

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access

NVD description · AI analysis pending
8.73%
Full article689 words · extracted from infosecurity-magazine.com · click to collapse

Citrix has released patches for three zero-day vulnerabilities in NetScaler ADC and Gateway, one of which was already being exploited by attackers.

The flaws, tracked as CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424, are two memory overflow vulnerabilities and an improper access control on the NetScaler Management Interface.

They are all considered critical vulnerabilities, with severity score (CVSS) ratings of 9.2, 8.8 and 8.7, respectively.

The following systems are affected by all three vulnerabilities:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-47.48
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-59.22
  • NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.241-FIPS and NDcPP
  • NetScaler ADC 12.1-FIPS and NDcPP before 12.1-55.330-FIPS and NDcPP

Additionally, Secure Private Access on-prem or Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities.

In an August 26 advisory, Citrix indicated that CVE-2025-7775 had been observed being exploited in the wild on “unmitigated appliances.”

According to independent security researcher Kevin Beaumont, exploit campaigns began before the patches were made available by Citrix.

He stated that CVE-2025-7775, which he dubbed ‘CitrixDeelb,’ is “the main problem, [with] pre-authentication remote code execution (RCE) being used to drop webshells to backdoor organizations.”

Based on initial internet scanning for hosts vulnerable to CVE-2025-7775, Beaumont said he found that 84% affected appliances were vulnerable as of August 26.

The Shadowserver Foundation observed at least 28,000 unpatched Citrix NetScaler instances vulnerable to the CVE-2025-7775 RCE vulnerability as of August 26.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-7775 to its Known Exploited Vulnerabilities (KEV) catalog on August 26 and said US federal agencies should apply patches by August 28.

Customers Urged to Patch Vulnerable Appliances

Citrix urged users to upgrade to one of the following patched versions:

  • NetScaler ADC and NetScaler Gateway 14.1-47.48 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-59.22 and later releases of 13.1
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.241 and later releases of 13.1-FIPS and 13.1-NDcPP
  • NetScaler ADC 12.1-FIPS and 12.1-NDcPP 12.1-55.330 and later releases of 12.1-FIPS and 12.1-NDcPP

No other workaround is available to mitigate the exploitation of one of these vulnerabilities.

The software developer also noted that NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now considered end-of-life (EOL) versions and are no longer supported.

“Customers are recommended to upgrade their appliances to one of the supported versions that address the vulnerabilities,” the Citrix advisory added.

Patching Is Not Enough, Experts Said

Simply applying patches without futher investigation of potential compromise is not sufficient, warned Benjamin Harris, CEO of WatchTowr.  

“Patching is critical, but patching alone won’t cut it. Unless organizations urgently review for signs of prior compromise and deployed backdoors, attackers will still be inside. Those that only patch will remain exposed,” he said.

Caitlin Condon, VP of security research at VulnCheck, argued that exploit campaigns are likely coming from sophisticated threat actors and hinted at involvement by nation-state groups.

"Memory corruption vulnerabilities like CVE-2025-7775 and CVE-2025-7776 can be tricky to exploit and on the whole tend to be used by state-sponsored or other skilled adversaries in targeted attacks rather than leveraged by commodity attackers broadly,” she said.

VulnCheck’s research has identified that another recent Citrix NetScaler vulnerability, CVE-2025-6543, which affects a narrower set of configurations, shares a nearly identical description with CVE-2025-7775. However, CVE-2025-6543 has not been exploited at scale despite its inclusion on VulnCheck’s Known Exploited Vulnerabilities (KEV) list since June 25, according to the firm.

While Citrix’s advisory explicitly confirms active exploitation only for CVE-2025-7775, VulnCheck’s Condon warned that "management interfaces for firewalls and security gateways have been targeted en masse in recent campaigns."

She emphasized the risk of future exploit chains combining an initial access flaw like CVE-2025-7775 with a secondary vulnerability such as CVE-2025-8424, with the ultimate goal of compromising management interfaces.

Condon urged organizations to prioritize patching CVE-2025-8424, cautioning that "vulnerability response shouldn’t focus solely on higher-severity memory corruption CVEs – some of which are harder to exploit – at the expense of more operationally critical flaws."

This article was updated on August 27 with the addition of CVE-2025-7775 in CISA's KEV catalog and evidence of thousands of vulnerable NetScaler appliances as observed by the Shadowserver Foundation.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/citrix-patch-netscaler-zero-days/