logo

Now everybody but Citrix agrees that CitrixBleed 2 is under exploit

ID: 8a5379b4-957f-5da5-bd7b-cbc786f1e884

STIX ID: report--8a5379b4-957f-5da5-bd7b-cbc786f1e884

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-07-10

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

CVE-2025-5777 ("CitrixBleed 2") is a critical (CVSS 9.3) memory-disclosure flaw in Citrix NetScaler ADCs configured as gateways or AAA servers that enables unauthenticated attackers to read session tokens, bypass multi-factor authentication, and hijack user sessions; working exploits have been published, CISA added the flaw to its Known Exploited Vulnerabilities catalog, and researchers report active exploitation and increased scanning, so affected customers are urged to install vendor-recommended builds immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.