Crooks turn HexStrike AI into a weapon for fresh vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-7775 | Actively Exploited Memory Overflow RCE/DoS in Citrix NetScaler ADC/Gateway CVE-2025-7775 is a memory overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution and/or denial of service. It is triggered when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual server, or — on 13.1, 14.1, 13.1-FIPS, and NDcPP builds — when load-balancing virtual servers of type HTTP, SSL, or HTTP_QUIC are bound with IPv6 services or servicegroups with IPv6 servers (including DBS IPv6), or a CR virtual server of type HDX is in use. A remote, unauthenticated attacker (CVSS 4.0 network vector with no privileges required) who triggers the memory overflow can execute code with high impact on confidentiality and integrity or crash the device. Organizations running NetScaler in these exposed configurations, notably as remote-access gateways, are affected. Exploitation is confirmed in the wild: Citrix has confirmed active exploitation, the flaw was added to CISA's KEV catalog on 2025-08-26, and EPSS estimates a 19.6% probability of exploitation within 30 days (97th percentile). Do: Upgrade all NetScaler ADC and Gateway appliances to the patched builds on the 13.1, 14.1, 13.1-FIPS, and NDcPP release trains identified in Citrix's security bulletin, prioritizing internet-facing devices. Audit configurations for Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual servers, HTTP/SSL/HTTP_QUIC LB virtual servers with IPv6 bindings, and CR virtual servers of type HDX to confirm exposure. The KEV listing makes applying vendor mitigations or the upgrade mandatory for US federal agencies under BOD 22-01. | 9.2 | 20% | KEV |
| large≈28,000+ internet-exposed NetScaler instances per public scans; total vulnerable deployments likely higher | |
| CVE-2025-7776 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is conf Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it NVD description · AI analysis pending | 8.8 | 7% |
| — | ||
| CVE-2025-8424 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Clus Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access NVD description · AI analysis pending | 8.7 | 3% | — | — |
Full article472 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 03, 2025

Threat actors abuse HexStrike AI, a new offensive security tool meant for red teaming and bug bounties, to exploit fresh vulnerabilities.
Check Point researchers warn that threat actors are abusing AI-based offensive security tool HexStrike AI to quickly exploit recently disclosed security flaws.
HexStrike AI combines professional security tools with autonomous AI agents to deliver comprehensive security testing capabilities.
HexStrike AI uses MCP Agents to connect LLMs with real offensive tools, orchestrating 150+ security utilities. It acts as a conductor, turning vague commands into precise steps for penetration testing, exploitation, and data exfiltration. This orchestration brain adapts in real time, automating complex attack workflows.
Malicious actors quickly attempted to weaponize HexStrike AI, discussing its use to exploit Citrix NetScaler zero-days, turning a defensive tool into an attack engine. Check Point researchers observed dark web posts discussing HexStrike AI, shortly after its release.
“Within hours of its release, dark web chatter shows threat actors attempting to use HexStrike-AI to go after a recent zero day CVEs, with attackers dropping webshells for unauthenticated remote code execution.” reads the report published by Check Point. “These vulnerabilities are complex and require advanced skills to exploit. With Hextrike-AI, threat actors claim to reduce the exploitation time from days to under 10 minutes.”

“But almost immediately after release, malicious actors began discussing how to weaponize it. Within hours, certain underground channels discussed application of the framework to exploit the Citrix NetScaler ADC and Gateway zero-day vulnerabilities disclosed last Tuesday (08/26).” continues the report.
“This marks a pivotal moment: a tool designed to strengthen defenses has been claimed to be rapidly repurposed into an engine for exploitation, crystallizing earlier concepts into a widely available platform driving real-world attacks.”
The use of “dual-use” AI tools shrink the gap between disclosure and mass exploitation, automates parallel attacks, and reduces human effort.
On August 26, Citrix disclosed 3 zero-days in NetScaler ADC/Gateway: CVE-2025-7775 (RCE, already exploited), CVE-2025-7776 (memory flaw, high-risk), CVE-2025-8424 (access control weakness). Exploitation was once complex, but Hexstrike-AI now automates scanning, exploit crafting, and payload delivery. Within 12h, threat actors discussed its use, even selling vulnerable instances. Attacks that took weeks can launch in minutes, at scale, with retries boosting success—shrinking disclosure-to-exploitation time.
“Hexstrike-AI is a watershed moment. What was once a conceptual architecture – a central orchestration brain directing AI agents – has now been embodied in a working tool. And it is already being applied against active zero days.” concludes the report. “The security community has been warning about the convergence of AI orchestration and offensive tooling, and Hexstrike-AI proves those warnings weren’t theoretical. What seemed like an emerging possibility is now an operational reality, and attackers are wasting no time putting it to use.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181878/cyber-crime/crooks-turn-hexstrike-ai-into-a-weapon-for-fresh-vulnerabilities.html