CISA orders agencies to immediately patch Citrix Bleed 2, saying bug poses ‘unacceptable risk’
ID: 86d3a802-ec1d-5e66-bc97-370977733a94
STIX ID: report--86d3a802-ec1d-5e66-bc97-370977733a94
Feed Name: The Record from Recorded Future News
The Cybersecurity and Infrastructure Security Agency (CISA) ordered federal civilian agencies to patch CVE-2025-5777 ("Citrix Bleed 2") within 24 hours after Citrix disclosed a critical (9.2) memory-disclosure vulnerability in NetScaler ADC/Gateway appliances that researchers and responders report is being actively exploited; the flaw can expose session tokens and enable MFA bypass, has been linked to ransomware-related activity, and prompted advisories from vendors and national bodies including the U.K. NHS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
