High severity7.5CISA KEVNVD Advisory· Published Jun 17, 2025· Updated Aug 4, 2026
CVE-2025-5777
CVE-2025-5777
Description
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*range: >=13.1,<13.1-58.32
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*range: >=12.1,<12.1-55.328
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*range: >=13.1,<13.1-37.235
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*Range: >=13.1,<13.1-58.32
- NetScaler/Gatewayv5Range: 14.1
Patches
Vulnerability mechanics
References
10- citrixbleed.comnvdBroken LinkThird Party Advisory
- doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71nvdThird Party Advisory
- horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/nvdThird Party Advisory
- labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/nvdThird Party Advisory
- reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/nvdThird Party Advisory
- support.citrix.com/support-home/kbsearch/articlenvdVendor Advisory
- www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/nvdPress/Media CoverageThird Party Advisory
- www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.theregister.com/2025/07/10/cisa_citrixbleed_kev/nvdPress/Media Coverage
News mentions
12- Ransomware Groups Increasingly Deploy EDR Kill TechniquesInfosecurity Magazine · Jul 27, 2026
- Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate NetworksCyber Security News · Jul 27, 2026
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News · Jul 13, 2026
- Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an HourCyber Security News · Jul 10, 2026
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThe Hacker News · Jul 2, 2026
- CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public DisclosureCyber Security News · Jul 2, 2026
- CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)watchTowr Labs · Jun 30, 2026
- INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023The Hacker News · Jun 18, 2026
- INC Ransomware Thrives by Mastering the BasicsDark Reading · Jun 17, 2026
- Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security RisksInfosecurity Magazine · Jun 15, 2026
- Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101)watchTowr Labs · Nov 12, 2025
- The Rise of Collaborative Tactics Among China-aligned Cyber Espionage CampaignsTrend Micro Research · Oct 22, 2025