'CitrixBleed 2' Shows Signs of Active Exploitation
ID: 47ce2000-bbd6-5009-a150-3dd6ec7bfe53
STIX ID: report--47ce2000-bbd6-5009-a150-3dd6ec7bfe53
Feed Name: Dark Reading
Threat Score
A critical out-of-bounds read vulnerability (CVE-2025-5777, "CitrixBleed 2") in Citrix NetScaler ADC and Gateway can expose session tokens and allow authentication bypass and prolonged access. ReliaQuest reports indicators consistent with active exploitation—hijacked Citrix sessions, session reuse across IPs, AD reconnaissance activity, and presence of ADExplorer64.exe—and Citrix has published patched releases that organizations should deploy immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
