logo

CVE-2025-5777: Critical Information Disclosure Vulnerability “Citrix Bleed 2” in Citrix NetScaler ADC and Gateway

ID: dbf6e983-b250-5757-bca0-4b817ab55d0f

STIX ID: report--dbf6e983-b250-5757-bca0-4b817ab55d0f

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2025-06-25

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On June 23, 2025 Arctic Wolf and Citrix updated advisories for multiple critical NetScaler vulnerabilities — notably CVE-2025-5777 (an out-of-bounds read labeled “Citrix Bleed 2”), CVE-2025-5349 (improper access control), and CVE-2025-6543 (a memory overflow with confirmed in-the-wild exploitation) — affecting NetScaler Gateway and ADC deployments; the advisory urges immediate upgrades to specified fixed builds, terminating active ICA/PCoIP sessions post-upgrade, and warns that customer-managed NetScaler appliances remain at risk while similar prior vulnerabilities were exploited by ransomware affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.