Over 1,200 Citrix servers unpatched against critical auth bypass flaw
ID: 80cd8ae8-4ad6-52e6-b1b1-868701d190f2
STIX ID: report--80cd8ae8-4ad6-52e6-b1b1-868701d190f2
Feed Name: Bleeping Computer
A critical Citrix NetScaler vulnerability (CVE-2025-5777, “Citrix Bleed 2”) allows unauthenticated attackers to read out-of-bounds memory, steal session tokens, hijack user sessions and bypass MFA; Shadowserver reports thousands of exposed unpatched appliances while ReliaQuest assesses with medium confidence that the flaw is being actively exploited with observed post-exploitation indicators (session reuse, LDAP queries). Citrix urges immediate patching and session termination; organizations should apply patches, review access controls, and monitor NetScaler gateways for suspicious sessions and AD reconnaissance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
