logo

'CitrixBleed 2' Shows Signs of Active Exploitation

ID: 47ce2000-bbd6-5009-a150-3dd6ec7bfe53

STIX ID: report--47ce2000-bbd6-5009-a150-3dd6ec7bfe53

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-06-27

Date Updated: 2026-04-21

Author: Kristina Beek

...
...

A critical out-of-bounds read vulnerability (CVE-2025-5777, "CitrixBleed 2") in Citrix NetScaler ADC and Gateway can expose session tokens and allow authentication bypass and prolonged access. ReliaQuest reports indicators consistent with active exploitation—hijacked Citrix sessions, session reuse across IPs, AD reconnaissance activity, and presence of ADExplorer64.exe—and Citrix has published patched releases that organizations should deploy immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.