logo

CISA orders agencies to immediately patch Citrix Bleed 2, saying bug poses ‘unacceptable risk’

ID: 86d3a802-ec1d-5e66-bc97-370977733a94

STIX ID: report--86d3a802-ec1d-5e66-bc97-370977733a94

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-07-11

Date Updated: 2026-05-01

...
...

The Cybersecurity and Infrastructure Security Agency (CISA) ordered federal civilian agencies to patch CVE-2025-5777 ("Citrix Bleed 2") within 24 hours after Citrix disclosed a critical (9.2) memory-disclosure vulnerability in NetScaler ADC/Gateway appliances that researchers and responders report is being actively exploited; the flaw can expose session tokens and enable MFA bypass, has been linked to ransomware-related activity, and prompted advisories from vendors and national bodies including the U.K. NHS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.