logo

CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands

ID: 4958fc31-155e-5cdd-9a75-653507461a27

STIX ID: report--4958fc31-155e-5cdd-9a75-653507461a27

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-07-07

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Multiple security researchers have disclosed and published proof-of-concept exploits for CVE-2025-5777 (CitrixBleed 2), a critical (CVSS 9.3) memory-leak vulnerability in Citrix NetScaler ADC/Gateway that can expose session tokens and enable MFA bypass and session hijacking; vendors have released patches but a significant portion of users remain unpatched and active exploitation has been observed or is expected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.