CVE detail
CVE-2025-5777
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 2
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
36 source links · newest first
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, an
newsthehackernews.comJul 2, 2026, 6:30 PM- CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)0day Fans
Well, well, well - once again, the cat has dragged us in and spat us out. Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?” Well, if you’re here, you likely fit into one of the following categories: * A dear reader, * A group therapy accomplice * A Groundhog Day fan club member Why? Because we once again find ourselves talking about Citrix NetScalers. Yes, that’s right, we’ve found another excuse to cr
newslabs.watchtowr.comJun 30, 2026, 7:35 PM - Hackers Abuse QEMU for Defense EvasionSecurityWeek
The machine emulator has been abused in at least two different campaigns distributing ransomware and remote access tools.
newswww.securityweek.comApr 20, 2026, 11:35 AM Citrix has fixed two vulnerabilities in NetScaler ADC and NetScaler Gateway, with the more serious flaw (CVE-2026-3055) potentially allowing attackers to extract active session tokens from the memory of affected devices. Anil Shetty, senior VP of Engineering with Cloud Software Group (Citrix’s parent company), stated on Saturday that Cloud Software Group “is not aware of any unmitigated exploit available for either CVE 2026-3055 or CVE 2026-4368.” Still, as both vulnerabilities can be exploited in low-complexity … More →
newswww.helpnetsecurity.comMar 24, 2026, 2:13 PMWith 24 new vulnerabilities known to be exploited by ransomware groups, the list now includes 1,484 software and hardware flaws.
newswww.securityweek.comJan 5, 2026, 3:13 PMA suspected Chinese-nexus threat group has been compromising Cisco email security devices and planting backdoors and log-purging tools on them since at least late November 2025, Cisco Talos researchers have shared. “Our analysis indicates that appliances with non-standard configurations (…) are what we have observed as being compromised by the attack,” they noted. According to the accompanying advisory, the attackers exploited CVE-2025-20393, an AsyncOS vulnerability stemming from improper input validation, to execute arbitrary commands with … More →
newswww.helpnetsecurity.comDec 17, 2025, 7:28 PM- From Patch Tuesday to Pentest Wednesday®: Proof That Redefined Security for a ManufacturerHorizon3.ai
Patch Tuesday is a known event, but attackers are moving faster than ever. For a leading U.S. manufacturer, shifting from simple patching to continuous validation became the key to proving their fixes worked, turning uncertainty into confidence.
exploithorizon3.aiDec 10, 2025, 5:00 PM - 17th November – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 17th November, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Cl0p’s Oracle E-Business Suite (CVE-2025-61882) zero-day campaign continues to expand. There are new confirmed breaches at The Washington Post, Logitech, Allianz UK, and GlobalLogic, as well as a newly listed but unconfirmed […]
vendorresearch.checkpoint.comNov 17, 2025, 11:04 AM The Amazon Threat Intelligence team has now disclosed an advanced persistent threat (APT) campaign that exploited vulnerabilities in Citrix systems and Cisco’s Identity Service Engine (ISE), allowing hackers to breach critical identity infrastructure even before the flaws were made publicly known. According to Amazon’s findings, attackers had exploited “insufficient input validation” in a public API […]
newswww.csoonline.comNov 13, 2025, 12:15 PMAmazon has seen a threat actor exploiting CVE-2025-20337 and CVE-2025-5777, two critical Cisco and Citrix vulnerabilities, as zero-days.
newswww.securityweek.comNov 13, 2025, 9:50 AM- Amazon alerts: advanced threat actor exploits Cisco ISE & Citrix NetScaler zero-daysSecurity Affairs
Amazon warns that an advanced threat actor exploited zero-days in Cisco ISE and Citrix NetScaler to deploy custom malware. Amazon’s threat intelligence researchers spotted an advanced threat actor exploiting two previously undisclosed zero-day flaws in Cisco Identity Service Engine (ISE) and Citrix NetScaler ADC to deliver custom malware. Attackers also exploited multiple undisclosed vulnerabilities. Amazon’s […]
newssecurityaffairs.comNov 13, 2025, 8:42 AM Citrix NetScaler ADC and NetScaler Gateway customers have been hit by a new round of zero day vulnerabilities that require urgent patching, including one the company warned is being actively exploited. That exploitation alert makes the highest priority flaw, CVE-2025-7775, the one admins will want to start with. According to Citrix’s advisory, it’s a memory […]
newswww.csoonline.comAug 28, 2025, 1:23 AMAttackers are exploiting a Citrix NetScaler vulnerability to breach critical organizations, notably in the Netherlands, but most likely in other countries as well. The Netherlands’ National Cyber Security Centre (NCSC) has tracked vulnerabilities caused by a memory overflow bug that allows threat actors to launch “sophisticated” remote code execution (RCE) and distributed denial of service […]
newswww.csoonline.comAug 13, 2025, 3:11 AM- Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543)Help Net Security
FortiGuard Labs has reported a dramatic spike in exploitation attempts targeting CitrixBleed 2, a critical buffer over‑read flaw (CVE‑2025‑5777) affecting Citrix NetScaler ADC (Application Delivery Controller) and Gateway devices. Since July 28, 2025, they have detected over 6,000 exploitation attempts, mostly in the US, Australia, Germany and the UK, “with adversaries primarily focusing on high-value sectors such as technology, banking, healthcare, and education.” Meanwhile, the Dutch National Cyber Security Centre (NCSC‑NL) has confirmed that another NetScaler … More →
newswww.helpnetsecurity.comAug 12, 2025, 2:38 PM GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
vendorwww.greynoise.ioJul 16, 2025, 12:00 AM- CitrixBleed 2 Flaw Poses Unacceptable Risk: CISASecurityWeek
CISA considers the recently disclosed CitrixBleed 2 vulnerability an unacceptable risk and has added it to the KEV catalog.
newswww.securityweek.comJul 14, 2025, 2:38 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. McDonald’s job app exposes data of 64 Million applicants Athlete or Hacker? Russian basketball player accused […]
newssecurityaffairs.comJul 13, 2025, 9:42 AM- Week in review: Microsoft fixes wormable RCE bug on Windows, check for CitrixBleed 2 exploitationHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) For July 2025 Patch Tuesday, Microsoft has released patches for 130 vulnerabilities, among them one that’s publicly disclosed (CVE-2025-49719) and a wormable RCE bug on Windows and Windows Server (CVE-2025-47981). Check for CitrixBleed 2 exploitation even if you patched quickly! (CVE-2025-5777) With PoC exploits for CVE-2025-5777 (aka CitrixBleed 2) now public and reports … More →
newswww.helpnetsecurity.comJul 13, 2025, 7:15 AM - U.S. CISA adds Citrix NetScaler ADC and Gateway flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler ADC and Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2025-5777, to its Known Exploited Vulnerabilities (KEV) catalog. The CVE-2025-5777 flaw, dubbed ‘CitrixBleed 2‘ (CVSS v4.0 Base Score of 9.3), […]
newssecurityaffairs.comJul 11, 2025, 8:19 AM Security researchers have released a technical analysis and proof-of-concept exploit code for a critical vulnerability fixed last month in Citrix NetScaler appliances that is suspected to have been exploited in the wild, though in a limited capacity and without official confirmation from Citrix. Companies are urged to deploy the patches and use published indicators of […]
newswww.csoonline.comJul 9, 2025, 11:37 PM- July Patch Tuesday: 14 critical Microsoft vulnerabilities, one SAP hole rated at 10 in severityCSO Online
Microsoft’s July Patch Tuesday fixes are a mix of good news and bad news for CSOs: Fourteen of the vulnerabilities are rated as critical, but on the other hand, there are no zero-days and only one vulnerability with a publicly available proof of concept. CSOs need to immediately address a heap-based buffer overflow vulnerability in […]
newswww.csoonline.comJul 8, 2025, 11:50 PM With PoC exploits for CVE-2025-5777 (aka CitrixBleed 2) now public and reports of active exploitation of the flaw since mid-June, you should check whether your Citrix NetScaler ADC and/or Gateway instances have been probed and compromised by attackers. Citrix’s current official line is that they have no evidence of in-the-wild exploitation and no indicators of compromise to share. Luckily, several security companies and researchers have provided some. CVE-2025-5777 exposed CVE-2025-5777 is an out-of-bounds memory read … More →
newswww.helpnetsecurity.comJul 8, 2025, 3:31 PMResearchers released technical information and exploit code targeting a critical vulnerability (CVE-2025-5777) in Citrix NetScaler.
newswww.securityweek.comJul 8, 2025, 12:04 PMBackground and Confusion On June 17, 2025, Citrix published an advisory detailing CVE-2025-5777 and CVE-2025-5349. Affected products include: On June 25, 2025, they also published an advisory detailing CVE-2025-6543. Affected products include: Of the three vulnerabilities, two of them have been receiving a bit of buzz: While we’ve developed a working exploit for one of […]
exploithorizon3.aiJul 7, 2025, 1:29 PM- 7th July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The International Criminal Court (ICC) disclosed a sophisticated cyber‐security incident in late June 2025, its second such event in recent years. The intrusion, which occurred in June 2025, was promptly detected and […]
vendorresearch.checkpoint.comJul 7, 2025, 10:57 AM - Week in review: Sudo local privilege escalation flaws fixed, Google patches actively exploited ChromeHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Sudo local privilege escalation vulnerabilities fixed (CVE-2025-32462, CVE-2025-32463) If you haven’t recently updated the Sudo utility on your Linux box(es), you should do so now, to patch two local privilege escalation vulnerabilities (CVE-2025-32462, CVE-2025-32463) that have been disclosed on Monday. Google patches actively exploited Chrome (CVE‑2025‑6554) Google has released a security update for Chrome to address a zero‑day vulnerability (CVE-2025-6554) … More →
newswww.helpnetsecurity.comJul 6, 2025, 8:00 AM - CVE-2025-5777Horizon3.ai
Citrix NetScaler Bleed 2
exploithorizon3.aiJul 3, 2025, 12:25 PM Many Citrix NetScaler systems are exposed to attacks exploiting the vulnerabilities tracked as CVE-2025-5777 and CVE-2025-6543.
newswww.securityweek.comJul 1, 2025, 9:40 AM- CitrixBleed 2 might be actively exploited (CVE-2025-5777)Help Net Security
While Citrix has observed some instances where CVE-2025-6543 has been exploited on vulnerable NetScaler networking appliances, the company still says that they don’t have evidence of exploitation for CVE-2025-5349 or CVE-2025-5777, both of which have been patched earlier this month. CVE-2025-5777, in particular, has captured the attention of infosec professionals due to its similarity to CVE-2023-4966, aka CitrixBleed. Consequently, CVE-2025-5777 has been informally dubbed “CitrixBleed 2” by security researcher Kevin Beaumont. Both CitrixBleed and CitrixBleed … More →
newswww.helpnetsecurity.comJun 30, 2025, 12:36 PM Citrix users are back in the crosshairs, as a new out-of-bounds read vulnerability, reminiscent of the notorious “Citrix Bleed,” has surfaced with signs already pointing to active exploitation. The vulnerability tracked as CVE-2025-5777 and dubbed “Citrix Bleed 2” by the researchers, is an insufficient input validation issue affecting Citrix NetScaler ADC and NetScaler Gateway devices, […]
newswww.csoonline.comJun 30, 2025, 11:24 AM- Week in review: Backdoor found in SOHO devices running Linux, high-risk WinRAR RCE flaw patchedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Stealthy backdoor found hiding in SOHO devices running Linux SecurityScorecard’s STRIKE team has uncovered a network of compromised small office and home office (SOHO) devices they’re calling LapDogs. High-risk WinRAR RCE vulnerability patched, update quickly! (CVE-2025-6218) A recently patched directory traversal vulnerability (CVE-2025-6218) in WinRAR could be leveraged by remote attackers to execute arbitrary code on affected installations. Breaking the … More →
newswww.helpnetsecurity.comJun 29, 2025, 7:40 AM - CitrixBleed 2: The nightmare that echoes the ‘CitrixBleed’ flaw in Citrix NetScaler devicesSecurity Affairs
New Citrix flaw ‘CitrixBleed 2’ lets attackers steal session cookies without logging in, echoing a previously exploited vulnerability. A new flaw in Citrix NetScaler ADC and Gateway, dubbed ‘CitrixBleed 2‘ (CVE-2025-5777, CVSS v4.0 Base Score of 9.3), can allow unauthenticated attackers to steal session cookies, similar to a past critical exploit. The vulnerability is an […]
newssecurityaffairs.comJun 26, 2025, 7:29 AM Citrix has released patches for a critical vulnerability in NetScaler ADC and NetScaler Gateway exploited as a zero-day.
newswww.securityweek.comJun 26, 2025, 7:02 AM- 23rd June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 23rd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Scania, a Swedish manufacturer of heavy trucks and engines, has suffered a data breach that resulted in the theft of insurance claim documents from its Financial Services systems via compromised credentials of […]
vendorresearch.checkpoint.comJun 23, 2025, 2:14 PM - Critical Citrix NetScaler bug fixed, upgrade ASAP! (CVE-2025-5777)Help Net Security
Citrix has fixed a critical vulnerability (CVE-2025-5777) in NetScaler ADC and NetScaler Gateway reminiscent of the infamous and widely exploited CitrixBleed flaw. The vulnerabilities have been privately disclosed and there is no indication that they are under active exploitation. Nevertheless, the company has urged to install the relevant updated versions as soon as possible and terminate active sessions. About the vulnerabilities (CVE-2025-5777, CVE-2023-4966) CVE-2025-5777 is an out-of-bounds read flaw stemming from insufficient input validation. Like … More →
newswww.helpnetsecurity.comJun 23, 2025, 11:12 AM Citrix has released patches for critical- and high-severity vulnerabilities in NetScaler and Secure Access Client and Workspace for Windows.
newswww.securityweek.comJun 18, 2025, 1:02 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-1848CVSS 7.8 · High
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnera…
- CVE-2024-1847CVSS 7.8 · High
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnera…
- CVE-2026-8451CVSS 8.8 · High
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
- CVE-2026-10817CVSS 6.9 · Medium
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual s…
- CVE-2026-3055CVSS 9.3 · Critical
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
- CVE-2026-66034CVSS 7.7 · High
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds…