CVE-2025-5777

Published Jun 17, 2025

Last updated 9 months ago

Exploit knownCVSS critical 9.3
NetScaler ADC
NetScaler Gateway
Citrix
VDI
Network
Zero-day
IoT
Server
OT

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-5777 is a vulnerability affecting NetScaler ADC and NetScaler Gateway. It is caused by insufficient input validation, which leads to a memory overread. The vulnerability can be exploited on devices configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. An unauthorized attacker could potentially grab valid session tokens from the memory of internet-facing NetScaler devices by sending a malformed request. Successful exploitation could allow the attacker to gain access to the appliances.

Description
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Source
secure@citrix.com
NVD status
Modified
Products
netscaler_application_delivery_controller, netscaler_gateway

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Exploit added on
Jul 10, 2025
Exploit action due
Jul 11, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@citrix.com
CWE-125
nvd@nist.gov
CWE-908
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-457

Social media

Hype score
Not currently trending
  1. 多要素認証(MFA)を済ませた正規のセッションが、その21分後に攻撃者のIPアドレスから操作されていた事例が報告されました。NetScaler(Citrixのゲートウェイ機器)で認証前にメモリ内容が漏れる脆弱性CitrixBle

    @MalwareBibleJP

    16 Jul 2026

    4266 Impressions

    2 Retweets

    19 Likes

    13 Bookmarks

    0 Replies

    1 Quote

  2. Anubis ransomware group exploited CitrixBleed 2 (CVE-2025-5777) to steal session tokens and bypass MFA across 91 organizations. Attackers used legitimate remote management tools for persistence and lateral movement before deploying ransomware. Runtime segmentation helps contain

    @aviatrixtrc

    13 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CitrixBleed 2 just handed Anubis ransomware a master key. Anubis affiliates are exploiting CVE-2025-5777 to extract session tokens from vulnerable NetScaler ADC/Gateway memory, with no password or MFA required. From there: RDP, RMM tools, credential dumping, cloud exfil, and

    @SecPod

    13 Jul 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CitrixBleed 2 just handed Anubis ransomware a master key. Anubis affiliates are exploiting CVE-2025-5777 to extract session tokens from vulnerable NetScaler ADC/Gateway memory, with no password or MFA required. From there: RDP, RMM tools, credential dumping, cloud exfil, and

    @SecPod

    13 Jul 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. MFA won’t save you from CitrixBleed 2 (CVE-2025-5777). Attackers are hijacking live session tokens to bypass security and deploy DragonForce ransomware. The fix: → Patch Citrix systems NOW. → Terminate all active sessions. Don't wait for the audit. #CyberSecurity https://

    @Techsico_IT

    12 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Citrix Admins: CitrixBleed 2 (CVE-2025-5777) is fueling DragonForce ransomware. Attackers are stealing session tokens to bypass auth entirely. ✓ Patch NetScalers NOW ✓ Terminate ALL active sessions Don't wait for an audit. #CyberSecurity https://t.co/p0BTGPisKO

    @Techsico_IT

    11 Jul 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Hackers exploited the CitrixBleed 2 vulnerability (CVE-2025-5777) in Citrix NetScaler appliances nearly two weeks before a public PoC was released. This underscores the need for proactive threat intelligence and rapid patch management to mitigate such risks effectively. https://t

    @dailytechonx

    10 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️ Attackers are exploiting CitrixBleed 2 (CVE-2025-5777) to steal active session tokens from NetScaler ADC/Gateway, replay authenticated sessions, and bypass MFA — leading to ransomware. Huntress tracked 6+ incidents Jan–Jun 2026, one ending in DragonForce. 🔹 Pre-a

    @techepages

    10 Jul 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Citrix admins: CitrixBleed 2 (CVE-2025-5777) is fueling DragonForce ransomware. Attackers harvest session tokens to bypass auth and deploy. Patch your NetScaler ADC/Gateway immediately. Is your remote access truly secure? #CyberSecurity https://t.co/7j6iQCxQjR

    @Techsico_IT

    10 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-5777: Is CitrixBleed 2 a Critical Failure of Cyber Hygiene? https://t.co/T1FAMFHPqX #CyberSecurity #CVE2025 #CitrixBleed

    @cyber_newsroom

    9 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2025-5777: Huntress' Hype Over CitrixBleed 2 Fails to Prove Impact https://t.co/QHWRULVrIi #CVE2025 #CitrixBleed #Ransomware

    @cyber_newsroom

    9 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-5777: CitrixBleed 2 Exposes Process Weaknesses in Ransomware Defense https://t.co/YV1AXmM4Ce #CyberSecurity #Ransomware #CVEs

    @cyber_newsroom

    9 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2025-5777: CitrixBleed 2's Exploitation Fuels Ransomware Rampage https://t.co/fb30A0Z2YC #CVE2025 #CitrixBleed2 #Ransomware

    @cyber_newsroom

    9 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2025-5777: CitrixBleed 2 Makes Ransomware Easy for Dragonforce https://t.co/DY7da0luez #CVE2025 #CitrixBleed2 #Ransomware

    @cyber_newsroom

    9 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2025-5777: CitrixBleed 2 Rapidly Fuels Dragonforce Ransomware Attacks https://t.co/xuv1E4RDIw #CVE20255777 #CitrixBleed #DragonforceRansomware

    @cyber_newsroom

    9 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2025-5777 "CitrixBleed 2" is being actively exploited by an IAB to steal live NetScaler sessions, escalate to SYSTEM via a registry symlink primitive, and deploy DragonForce ransomware, all in under an hour across multiple unrelated orgs. - CVE-2025-5777 is a pre-auth memory

    @DFIR_Radar

    9 Jul 2026

    192 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 実環境での悪用が続く認証前脆弱性CitrixBleed-2(CVE-2025-5777)が、Anubisランサムウェアの侵入口の一つとして使われていることが明らかになっています。一連の侵害では、正規の遠隔管理ツールやCloudflareのトンネ

    @MalwareBibleJP

    6 Jul 2026

    1205 Impressions

    1 Retweet

    13 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  18. It's Already When. — Field Note Anubis affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) for ransomware access while FortiBleed actors monetize thousands of compromi... https://t.co/Ez8KKT9n8R #CyberSecurity #BlueTeam

    @itsalreadywhen

    3 Jul 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Ransomware isn't a malware problem, it's a credential handover nobody caught. CVE-2025-5777 handed Anubis session tokens; RMM tools handled the rest. QuanChain rotates 20 security levels in <200ms, before lateral movement completes. Is rotation speed now the real perimeter?

    @Quan_Chain

    3 Jul 2026

    239 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Anubis ransomware affiliates are exploiting CVE-2025-5777, a CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway, to get inside networks. Once in, they use legitimate RMM tools including ScreenConnect, Zoho Assist, and MeshAgent to blend with normal IT #infosec #c

    @Mr_viind

    3 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Anubis ransomware exploits Citrix Bleed 2 (CVE-2025-5777) for initial access. Affiliates abuse RMM tools, VPN credentials, and cloud transfer tools for data theft. For More: https://t.co/1TdAS6ZZlf #AnubisRansomware #CitrixBleed2 #CVE #Ransomware #RaaS #BYOVD #RMMAbuse #VECT ht

    @redsecuretech

    3 Jul 2026

    80 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 1/3 Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) to gain initial access. They use ScreenConnect, Zoho Assist, and MeshAgent to blend in as normal IT activity. Anubis is a rebrand of Sphinx RaaS, active since late 2024. #ransomware #CVE #cybersecurity

    @CyberTLDR

    3 Jul 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  23. 80% of recent ransomware breaches use Citrix Bleed 2 (CVE-2025-5777) as initial entry. This isn’t theory; it’s active, ongoing exploitation. #CyberSecurity #InfoSec #VAPT

    @ThreatRix_Ai

    3 Jul 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  24. the company disclosed a significant scale breach. data we'll see leaked next month. lesson: every internet-facing service should age out quarterly. #Citrix #ransomware #OpenSource #CVE-2025-5777 https://t.co/hpOdrGCDAV

    @trerbbb

    2 Jul 2026

    78 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials: Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.… https://t.co/MFU7v2AA8l https:/

    @shah_sheikh

    2 Jul 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Anubis ransomware affiliates are exploiting CitrixBleed 2 (CVE-2025-5777) and abusing legitimate RMM tools plus Cloudflared tunnels to blend into target environments across 2026 intrusions. Key findings: - Initial access comes via two paths: stolen VPN credentials and https://t

    @DFIR_Radar

    1 Jul 2026

    219 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  27. Arctic Wolf ontdekt Anubis-ransomware die CitrixBleed 2 (CVE-2025-5777) en legitieme RMM-tools misbruikt om onder de radar te blijven. https://t.co/jDVNWyBQHW #Security #Anubis #ArcticWolf #CitrixBleed2 #CVE20255777

    @Techzinenlbe

    1 Jul 2026

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Arctic Wolf has discovered Anubis ransomware that exploits CitrixBleed 2 (CVE-2025-5777) and legitimate RMM tools to stay under the radar. https://t.co/fuxOV6SaHF #Security #Anubis #ArcticWolf #CitrixBleed2 - Follow for more

    @techzine

    1 Jul 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. In our latest investigation, Arctic Wolf provides new insight into initial access techniques in #Anubis ransomware cases, including exploitation of #CitrixBleed 2 (CVE-2025-5777). Learn more: https://t.co/e8aaEcfokU #EndCyberRisk https://t.co/SdT3ysSVbW

    @AWNetworks

    1 Jul 2026

    222 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Hackers are exploiting QEMU VMs to create reverse SSH tunnels for deploying ransomware and RATs. Campaigns STAC4713 and STAC3725 leveraged SonicWall VPNs, SolarWinds CVE-2025-26399, and CitrixBleed2 CVE-2025-5777. #GoldEncounter #QEMUAbuse #USA https://t.co/cis34haini

    @TweetThreatNews

    21 Apr 2026

    255 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Top 5 Trending CVEs: 1 - CVE-2022-40769 2 - CVE-2025-5777 3 - CVE-2025-8088 4 - CVE-2023-41064 5 - CVE-2026-21643 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    5 Apr 2026

    256 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. IR/CERT Morning Brief Today’s brief centered on exploitable enterprise exposure and follow-on access risk: Citrix NetScaler CVE-2025-5777 / CVE-2025-5349, SAP NetWeaver abuse tied to the “10KBLAZE” cluster, SonicWall SMA credential exposure concerns, and ClickFix-style mal

    @Team_D4rkn3ttz

    5 Apr 2026

    305 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    5 Replies

    0 Quotes

  33. TRC analysis shows attackers exploiting CVE-2025-5777 in Citrix NetScaler to read sensitive memory contents including session tokens and credentials. The memory overread vulnerability enables lateral movement through compromised authentication systems. Runtime segmentation helps

    @aviatrixtrc

    28 Mar 2026

    124 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. TRC analysis shows attackers exploiting CitrixBleed 2 (CVE-2025-5777) to steal session tokens from NetScaler SAML providers, then escalating privileges for admin access. Over 100 organizations compromised despite patches being available. Runtime segmentation helps limit

    @aviatrixtrc

    26 Mar 2026

    129 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. TRC analysis shows attackers exploiting CVE-2025-5777 to extract session tokens from Citrix NetScaler memory, then moving laterally through networks with stolen credentials. Runtime segmentation helps contain such post-compromise activity by limiting blast radius. #ZeroTrust

    @aviatrixtrc

    25 Mar 2026

    143 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Top 5 Trending CVEs: 1 - CVE-2026-21992 2 - CVE-2025-5777 3 - CVE-2026-3909 4 - CVE-2025-32975 5 - CVE-2008-0166 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    24 Mar 2026

    179 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. ⚠️ We are observing an active exploitation campaign targeting Citrix NetScaler instances We have observed 500+ exploit attempts of both CitrixBleeds (CVE-2025-5777 and CVE-2023-4966) against our NetScaler decoys across multiple regions: 193.24.211.86 AS215929 🇧🇬 Data

    @DefusedCyber

    16 Mar 2026

    10826 Impressions

    25 Retweets

    66 Likes

    25 Bookmarks

    1 Reply

    1 Quote

  38. 🚨 زيادة اختراقات وحملات إلكترونية عالمية ملخص الأسبوع: تقرير يكشف عن تصاعد الاختراقات الأمنية والإجراءات التنظيمية وتطورات الجريمة الإلكترونية حول ال

    @MisbarSec

    14 Feb 2026

    32 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Cytellite recent detection targeting CVE-2025-5777 — ZEN-ECN Visit -- https://t.co/S4tqaJzvww #Loginsoft #Cytellite #Cybersecurity #CVE20255777 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/AgvAT8LfZh

    @Loginsoft_Intel

    14 Jan 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Cytellite recent detection targeting CVE-2025-5777 — ZEN-ECN Visit -- https://t.co/S4tqaJzvww #Loginsoft #Cytellite #Cybersecurity #CVE20255777 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/gOwQThkcia

    @Loginsoft_Intel

    14 Jan 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. (THREAD) 1/5 🚨 **UPDATE on CitrixBleed 2 Vulnerability!** This critical flaw (CVE-2025-5777) is wreaking havoc, especially for crypto firms. Here’s what you need to know:

    @btc_box_

    1 Dec 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  42. #ICYMI Amazon honeypot service detected exploitation attempts for the Citrix Bleed Two vulnerability (CVE-2025-5777) prior to public disclosure, indicating a threat actor had been exploiting the vulnerability as a zero-day. https://t.co/ntkCi3KJnt #threatintel #deception

    @jc_vazquez

    28 Nov 2025

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚩 Amazon Uncovers Attacks Exploiting Cisco ISE and Citrix NetScaler as Zero-Day Flaws https://t.co/6iKbcRSPWl Amazon's MadPot honeypot network detected advanced threat actors exploiting two zero-days: CVE-2025-5777 (Citrix Bleed 2) and CVE-2025-20337 (Cisco ISE RCE) to deplo

    @Huntio

    22 Nov 2025

    1129 Impressions

    4 Retweets

    9 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  44. 🚨 Pennsylvania AG Breach Exposes SSNs via Citrix Bleed 2 INC ransomware gang exploited Citrix Bleed 2 (CVE-2025-5777) to breach Pennsylvania's Office of the Attorney General, stealing SSNs and medical information. What's concerning: the August attack disrupted the state's

    @the_c_protocol

    18 Nov 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 📢 𝐇𝐨𝐭 𝐨𝐟𝐟 𝐭𝐡𝐞 𝐩𝐫𝐞𝐬𝐬: 𝐂𝐕𝐄 𝐢𝐧𝐬𝐢𝐠𝐡𝐭𝐬! See how CVE-2025-5777 led to a major ransomware breach at the Pennsylvania AG's office. Learn defense tactics and breach insights in this deep-dive. 📖 Check the de

    @PurpleOps_io

    18 Nov 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Zero-Day Threats Strike Cisco and Amazon Systems! Critical zero-day vulnerabilities in Cisco ISE (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777) were exploited in the wild before patches were released, enabling attackers to install stealth web shells and gain administrator

    @ChbibAnas

    16 Nov 2025

    37 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Actively exploited CVE : CVE-2025-5777

    @transilienceai

    15 Nov 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  48. Amazon uncovered an advanced APT simultaneously exploiting Cisco ISE RCE (CVE-2025-20337) and Citrix Bleed Two (CVE-2025-5777) as zero-days. The attacker deployed a custom in-memory web shell on Cisco ISE. #CiscoZeroDay #CitrixHack #Cyberespionage https://t.co/Ra8EmmvliU

    @Daily_CyberSec

    14 Nov 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. An advanced threat actor exploited the critical vulnerabilities “Citrix Bleed 2" (CVE-2025-5777) in NetScaler ADC and Gateway, and CVE-2025-20337 affecting Cisco Identity Service Engine (ISE) as zero-days to deploy custom malware. https://t.co/8Tc9omcR04

    @blackwired32799

    14 Nov 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🍯@aws discovers APT exploiting Cisco and Citrix zero-days. Honeypot service detected exploitation attempts for the Citrix Bleed Two vulnerability (CVE-2025-5777) prior to public disclosure. https://t.co/ntkCi3KJnt #cybersecurity #threatintel #deception

    @jc_vazquez

    13 Nov 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations