logo

Citrix Gear Under Active Attack Again With Another Zero-Day

ID: bebb1e34-4e70-5fc8-9000-ad2a69ceb6fe

STIX ID: report--bebb1e34-4e70-5fc8-9000-ad2a69ceb6fe

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-08-26

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

Citrix disclosed three critical vulnerabilities in NetScaler ADC and NetScaler Gateway, notably CVE-2025-7775 (CVSS 9.2), a memory overflow zero-day observed in active exploitation that can allow remote system takeover or denial-of-service; two additional high-severity flaws (CVE-2025-7776 and CVE-2025-8424) could cause unpredictable behavior or improper access. The weaknesses affect multiple supported and unsupported release lines (12.1, 13.1, 14.1), pose a high risk because appliances sit at the network perimeter, and Citrix and security vendors strongly urge immediate patching while warning that a significant number of devices remain on end-of-life versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.