logo

Don't panic, but it's only a matter of time before critical 'CitrixBleed 2' is under attack

ID: f1cee43c-6161-597c-8bca-dc45b05a9e4d

STIX ID: report--f1cee43c-6161-597c-8bca-dc45b05a9e4d

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-06-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical unauthenticated out-of-bounds read vulnerability (CVE-2025-5777, CVSS 9.3) affects Citrix NetScaler ADC and NetScaler Gateway builds and can expose session tokens, enabling impersonation and MFA bypass; while no active exploitation has been reported yet, analysts warn it closely resembles the prior CitrixBleed flaw that was widely exploited by ransomware gangs, and organizations are strongly advised to apply vendor patches and recommended remediation steps immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.