ZeroHour
The Recordpublished ()ingested

Citrix warns of exploitation of Netscaler devices through new bugs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-5349
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

NVD description · AI analysis pending
8.75%
  • citrix netscaler application delivery controller
  • citrix netscaler gateway
CVE-2025-5777
Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned.

Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw.

9.3100% KEV ransomware
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of…
CVE-2025-6543
Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild

Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known.

Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading.

9.210% KEV
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
large≈50,000+ internet-exposed NetScaler ADC/Gateway devices (only Gateway/AAA configurations vulnerable)
Full article363 words · extracted from therecord.media · click to collapse

Hackers are exploiting a new vulnerability affecting several NetScaler products used by companies to manage network traffic.

Citrix published an advisory on Wednesday about CVE-2025-6543, a vulnerability carrying a severity score of 9.2 out of 10 that affects its Netscaler ADC and Netscaler Gateway appliances. The company said exploits of the vulnerability “on unmitigated appliances have been observed.”

Citrix urged customers to install updated versions of the software.

The advisory follows concerns about two other Netscaler vulnerabilities, tagged as CVE-2025-5349 and CVE-2025-5777. In its advisory last week, Citrix did not say if the bugs had already been exploited. 

Researchers have speculated that the three bugs are likely connected but Citrix did not respond to requests for comment. 

Experts compared the vulnerabilities from last week to Citrix Bleed — a widely exploited bug in 2023 that was used by ransomware gangs and nation-states to attack dozens of government organizations and major companies including Boeing and Toyota

Cybersecurity expert Kevin Beaumont, who dubbed the recent bugs as “Citrix Bleed 2,” warned that thousands of NetScaler installations are exposed to the internet. CVE-2025-5349 and CVE-2025-5777 allow threat actors to read sensitive data that could be used to bypass multifactor authentication, he added. 

The U.K.’s National Health Service released its own notice comparing the first two published vulnerabilities to Citrix Bleed, reiterating that the 2023 bug was heavily exploited by ransomware gangs. 

CVE-2025-5777 could expose “sensitive information such as session tokens,” the NHS said. 

“Attackers could use these tokens to hijack existing sessions, allowing access into the network, bypassing authentication controls such as multi-factor authentication (MFA),” they added. 

The original Citrix Bleed bug caused alarm among defenders because of how many hospitals and critical infrastructure organizations use NetScaler ADC and NetScaler Gateway.

The U.S. Cybersecurity and Infrastructure Security Agency warned more than 300 organizations in 2023 of their exposure to Citrix Bleed.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/citrix-warns-netscaler-exploitation-bug