CVE-2025-7775

Published Aug 26, 2025

Last updated 2 days ago

Exploit knownCVSS critical 9.2
NetScaler ADC
NetScaler Gateway

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-7775 is a memory overflow vulnerability that affects Citrix NetScaler ADC and NetScaler Gateway. It can lead to remote code execution (RCE) and/or denial of service (DoS). The vulnerability exists when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. It also affects load balancing (LB) virtual servers of types HTTP, SSL, or HTTP_QUIC bound with IPv6 services or service groups, as well as DBS IPv6 services or CR virtual server with type HDX. Exploits of this vulnerability have been observed in the wild.

Description
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX
Source
secure@citrix.com
NVD status
Analyzed
Products
netscaler_application_delivery_controller, netscaler_gateway

Insights

Analysis from the Intruder Security Team
Published Aug 28, 2025 Updated Aug 28, 2025

As this vulnerability is known to have been exploited by real attackers, the patch should be applied immediately.

If you have a vulnerable device connected to the internet, as well as patching, it is important to check that the device was not already compromised.

NCSC-NL, the Dutch National Cybersecurity Centre, have produced a tool available here which can help with this. Note that despite being marked as for an older CVE, this script is also receiving updates to check for issues relating to CVE-2025-7775.

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Citrix NetScaler Memory Overflow Vulnerability
Exploit added on
Aug 26, 2025
Exploit action due
Aug 28, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@citrix.com
CWE-119

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

22

  1. ⚠️ Citrix NetScaler – vom CVE zum Operator-Handbuch Das BSI meldet kritische Lücken (CVE-2025-7775/7776/8424). Doch ein Patch-Hinweis ersetzt kein Playbook für SOC & BlueTeams. 👉 Mein Citrix Operator Briefing schließt die Lücke: 🔹 Exploit-Flows visualisiert

    @stefanab77

    29 Aug 2025

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Weekly vuln radar. https://t.co/Cd6L8ACyLV – spot what’s trending before it’s everywhere: CVE-2025-53770 CVE-2025-43300 CVE-2025-5777 CVE-2024-21887 CVE-2023-46604 (@ThreatBookLabs) CVE-2025-7776 CVE-2025-54309 CVE-2025-7775 CVE-2025-53771 https://t.co/q4Rx5wWFSt

    @ptdbugs

    29 Aug 2025

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Citrix Netscaler ADCおよびGatewayの脆弱性(CVE-2025-7775)に関する注意喚起 - 一般社団法人 JPCERT コーディネーションセンター(JPCERT/CC) https://t.co/UM2QOZNsRq

    @kawn2020

    29 Aug 2025

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 【緊急】Citrix NetScaler ADC / Gateway に深刻な脆弱性 (CVE-2025-7775 / 7776 / 8424)について JPCERT/CC が注意喚起を更新📢 CVE-2025-7775 は既に悪用が確認されており、早急な対応が必要です。 詳細👇 https://t.co/Iv1uVdvMX

    @esunekk

    29 Aug 2025

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 【更新】Citrix Netscaler ADCおよびGatewayの脆弱性(CVE-2025-7775)に関する注意喚起を更新。脆弱性の影響を受ける対象のバージョンの記載に一部誤りがあり修正いたしました。謹んでおわび申し上げます。また、対

    @jpcert

    29 Aug 2025

    2643 Impressions

    6 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛡️ Cyber Threat Digest – 2025-08-28 KEV: CVE-2025-7775 — Citrix NetScaler Memory Overflow NVD: CVE-2018-25115 — Multiple D-Link DIR-series routers News: Google shares workarounds for auth failures… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    28 Aug 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🛡️ Cyber Threat Digest – 2025-08-28 KEV: CVE-2025-7775 — Citrix NetScaler Memory Overflow Vulnerability NVD: CVE-2025-40779 — a DHCPv4 client sends a News: Google shares workarounds for auth failures on… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    28 Aug 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. More than 28,200 Citrix instances are vulnerable to a critical remote code execution vulnerability tracked as CVE-2025-7775 that is already being exploited in the wild. https://t.co/9lsohHloD2

    @blackwired32799

    28 Aug 2025

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-7775: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution Vulnerability Exploited in the Wild https://t.co/ZUmS2wQvQQ https://t.co/rswfPw4Oif

    @secured_cyber

    28 Aug 2025

    178 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ⚠️ Over 28,200 Citrix NetScaler Instances Vulnerable to Actively Exploited RCE (CVE-2025-7775) https://t.co/il6AFvqGNW According to Shadowserver Foundation, more than 28,200 Citrix NetScaler ADC and Gateway systems, including over 10,000 in the U.S., are exposed to a critic

    @Huntio

    28 Aug 2025

    1164 Impressions

    6 Retweets

    14 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  11. Citrix Netscaler ADCおよびGatewayの脆弱性(CVE-2025-7775)に関する注意喚起 https://t.co/INVvqPxXkF

    @ohhara_shiojiri

    28 Aug 2025

    122 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Citrix, NetScaler ADC ve NetScaler Gateway ürünlerindeki üç kritik güvenlik açığını gidermek üzere acil yamalar yayınladı. Özellikle dikkat çekilmesi gereken nokta, CVE-2025-7775 kodlu zafiyetin siber saldırganlar tarafından aktif olarak istismar edildiğinin do

    @et2mas

    28 Aug 2025

    234 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. 🚨 Have you been busy patching against the new critical Citrix vulnerability dubbed CVE-2025-7775? We have found a comprehensive list of all internet-facing devices that are vulnerable. https://t.co/clAwPIJX4p

    @IntCyberDigest

    28 Aug 2025

    462 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  14. A critical zero-day vulnerability (CVE-2025-7775) endangering over 28,000 Citrix servers worldwide is being actively exploited by cybercriminals. With serious implications for enterprise security, immediate patching is essential to prevent extensive damage, as attackers can ex...

    @CybrPulse

    28 Aug 2025

    219 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. Attackers exploiting NetScaler ADC and Gateway zero day flaw, Citrix warns That exploitation alert makes the highest priority flaw, CVE-2025-7775 https://t.co/2tBhQ04xGF

    @wikinger7

    28 Aug 2025

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2025-7775の件、攻撃を喰らうとWebShell仕込まれるとか情報出てましたが、Nationaal Cyber Security Centrum (NCSC-NL)が、公開しているツールでログチェックできるようです。 https://t.co/bMwvZunius

    @tadmaddad

    27 Aug 2025

    3088 Impressions

    9 Retweets

    29 Likes

    10 Bookmarks

    1 Reply

    0 Quotes

  17. Guess what, more edge device exploitation … CVE-2025-7775 Citrix Pre-auth RCE. Citrix NetScaler ADC and NetScaler Gateway “Exploits of CVE-2025-7775 on unmitigated appliances have been observed.” Vendor: https://t.co/XuSWJISqZm IOC checker https://t.co/g9MXoouEG7 http

    @sneakymonk3y

    27 Aug 2025

    830 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  18. Citrix Fixes NetScaler Vulnerabilities, CVE-2025-7775 Actively Exploited https://t.co/Qg5sGGhxtx https://t.co/aGQ0JZxTWK

    @sctocs25

    27 Aug 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Citrix and cybersecurity researchers warn a critical, zero-day vulnerability affecting multiple versions of Citrix NetScaler products is under active exploitation. Citrix issued a security bulletin about the vulnerability — CVE-2025-7775 — and urged customers on affected vers

    @CyberScoopNews

    27 Aug 2025

    610 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. CVE-2025-7775: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution Vulnerability Exploited in the Wild https://t.co/ncXdVM1cqk https://t.co/SE9aVId28i

    @ggrubamn

    27 Aug 2025

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild Read more: https://t.co/KEx2u5pJjv A critical zero-day remote code execution (RCE) vulnerability, tracked as CVE-2025-7775, is affecting over 28,000 Citrix instances worldwide. More th

    @The_Cyber_News

    27 Aug 2025

    1399 Impressions

    4 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  22. Over 28,200 Citrix devices are vulnerable to a critical RCE flaw (CVE-2025-7775) actively exploited in the wild. 🚨 https://t.co/nrUgnaXErK #Citrix #RCE #Exploited #CyberSecurity #InfoSec

    @0xT3chn0m4nc3r

    27 Aug 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. #Cybersecurity #Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775 https://t.co/7U1mW6OqZ7

    @jos1727

    27 Aug 2025

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Citrix corrige trois failles critiques dans NetScaler ADC et NetScaler Gateway, dont une RCE zero-day (CVE-2025-7775) activement exploitée et ajoutée dans la KEV. https://t.co/2IN450bE1j

    @cert_ist

    27 Aug 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. NetScaler ADC/Gatewayの重大脆弱性とは?CVE-2025-7775を含む内容・被害事例・対策を解説 #cybernote #ブログ仲間と繋がりたい #Webライター https://t.co/XgTDdoaaVa

    @Teeeda_worker

    27 Aug 2025

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. NetScaler ADC/Gatewayの重大脆弱性とは?CVE-2025-7775を含む内容・被害事例・対策を解説 #cybernote #ブログ仲間と繋がりたい #Webライター https://t.co/LFAuYxFnDQ

    @CyberNote_media

    27 Aug 2025

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🗞️ Citrix has just rolled out patches for three significant vulnerabilities in its NetScaler ADC and Gateway products, with one of the flaws, a critical remote code execution vulnerability (CVE-2025-7775), already being actively exploited in the wild. Patch now!

    @gossy_84

    27 Aug 2025

    380 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  28. Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775 https://t.co/DUnmYOge9W #CyberSecurity #Patches #CSCIS

    @CIDC_Ops

    27 Aug 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Citrix Alert CVE-2025-7775 is being actively exploited to gain RCE and DoS on NetScaler ADC/Gateway. Added to CISA KEV. Patch now to 14.1-47.48+ or 13.1-59.22+. No workarounds available. #CyberSecurity #NetScaler #CVE20257775 #Infosec #PatchNow https://t.co/chP88UQ5eo

    @CloneSystemsInc

    27 Aug 2025

    231 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Citrix Patches Exploited NetScaler Zero-Day (CVE-2025-7775) - https://t.co/BdU53f5JVK

    @SecurityWeek

    27 Aug 2025

    1648 Impressions

    3 Retweets

    10 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  31. 🚨Critical RCE in #NetScaler ADC/Gateway (CVE-2025-7775) exploited in the wild! Memory overflow vulnerability impacts VPN & LB servers. No patch yet – urgent risk review & mitigation needed! 🔗https://t.co/fFnIFbwcAP https://t.co/UNiiekR9rB

    @rapidriskradar

    27 Aug 2025

    239 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. CVE-2025-7775: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution Vulnerability Exploited in the Wild https://t.co/iLY6i6lol1 https://t.co/pPL3Qx4Uq7

    @Art_Capella

    27 Aug 2025

    179 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CVE-2025-7775: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution Vulnerability Exploited in the Wild https://t.co/R4RNS8scjc https://t.co/yPLwBcwhVW

    @Trej0Jass

    27 Aug 2025

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CVE-2025-7775: Critical #Citrix #NetScaler Zero-Day #RCE Exploited to Drop Webshells #PATCHNOW #arcticwolf https://t.co/RIzrPH4kTQ

    @ervik

    27 Aug 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. #Citrix has announced an actively exploited RCE 0-day: CVE-2025-7775. No workarounds or mitigations. Make patching a priority. https://t.co/sQAMvWkh2O

    @ct_is

    27 Aug 2025

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. ALERT: On 2025-08-26 over 28.2K Citrix instances were unpatched to CVE-2025-7775 RCE. There is exploitation in the wild confirmed by @CISACyber KEV. Patch info from Citrix: https://t.co/JXKj8E4KtA Top affected: US, Germany Dashboard geo breakdown: https://t.co/5HfXP433yz https

    @Shadowserver

    27 Aug 2025

    8114 Impressions

    30 Retweets

    46 Likes

    17 Bookmarks

    1 Reply

    4 Quotes

  37. ⚠️⚠️ CVE-2025-7775(CVSS 9.2) Citrix Patches Three NetScaler Flaws in NetScaler ADC and NetScaler Gateway 🎯128k+ Results are found on the https://t.co/pb16tGYaKe nearly year 🔗FOFA Link: https://t.co/nrKy0cSZS6 FOFA Query:app="citrix-ADC" || app="citrix-Access-Gateway

    @fofabot

    27 Aug 2025

    1725 Impressions

    6 Retweets

    13 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 ZERO-DAY ALERT: Citrix NetScaler under active attack ⚠️ 🛑 CVE-2025-7775 → memory-overflow bug enables unauthenticated RCE 🌐 Exploited in the wild, hitting vulnerable ADC & Gateway appliances ⛔ No mitigations patch is the only defense 📌 Update to: 14.1

    @Newtalics

    27 Aug 2025

    219 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 🚨 Citrix patches critical NetScaler RCE flaw CVE-2025-7775 exploited in zero-day attacks, urging users to update immediately. https://t.co/mNmes6BwM9

    @not2cleverdotme

    27 Aug 2025

    173 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Citrix Netscaler ADCおよびGatewayの脆弱性(CVE-2025-7775)に関する注意喚起を公開。国内での悪用は未確認ですが、今後脆弱性の詳細が公表され、悪用が広がる可能性が高いため、開発者などから公開される最新の情

    @jpcert

    27 Aug 2025

    8017 Impressions

    6 Retweets

    15 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  41. 統合版 JPCERT/CC | 注意喚起: Citrix Netscaler ADCおよびGatewayの脆弱性(CVE-2025-7775)に関する注意喚起 (公開) https://t.co/I0qq5My2b3 #itsec_jp

    @itsec_jp

    27 Aug 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 🚨 @citrix / @NetScaler zero-day exploited 🚨 ⚠️ CVE-2025-7775 (pre-auth RCE/DoS) already used in the wild ⚠️ Exploit = webshell + backdoor persistence ⚠️ Citrix: Patch ASAP, no workarounds Why do Citrix zero-days keep getting hammered in 2025? 🗨️ Reply wit

    @TechNadu

    27 Aug 2025

    444 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨 New KEV Alert: @CISACyber adds CVE-2025-7775 – Citrix NetScaler Memory Overflow to its Known Exploited Vulnerabilities catalog. ⚠️ Active exploitation detected. 🔒 Federal agencies & all orgs urged to patch immediately. 💬 How do you monitor KEV updates? Foll

    @TechNadu

    27 Aug 2025

    251 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. CITRIX NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424 Multiple vulnerabilities have been discovered https://t.co/txSGtFuAeF

    @_CYOPS

    27 Aug 2025

    179 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. #Citrix patches three critical NetScaler flaws, including actively exploited CVE-2025-7775, urging users to update immediately to prevent attacks. #Cybersecurity #NetScaler #CVE2025 #InfoSec #TechUpdate #SecurityAlert https://t.co/w49JkJl8nq

    @TechStackQueen

    27 Aug 2025

    0 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Citrix NetScaler – CVE-2025-7775 : une nouvelle zero-day exploitée dans des attaques ! https://t.co/3MQzyavaRF

    @ITConnect_fr

    27 Aug 2025

    706 Impressions

    2 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  47. Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775 https://t.co/q5Y4AyVto1

    @ByteCheck101

    27 Aug 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. NetScaler (Citrix) ADC/Gatewayで認証前コード実行の脆弱性がCVE-2025-7775 ゼロデイとして修正。本日時点で稼働する該当機器を調査するとグローバルで29901台、国内で374台、海外各国にも日系大手資産多数あり。侵害調

    @nekono_naha

    27 Aug 2025

    3483 Impressions

    7 Retweets

    29 Likes

    9 Bookmarks

    0 Replies

    0 Quotes

  49. IPA 重要 | NetScaler ADCおよびNetScaler Gatewayの脆弱性について (CVE-2025-7775等) https://t.co/iEml5N7HvV #itsec_jp

    @itsec_jp

    27 Aug 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🚨Alert🚨CVE-2025-7775 (CVSS 9.2) : Memory Overflow Vulnerability Leading to Remote Code Execution and/or Denial-of-Service 📊183.9K+Services are found on the https://t.co/ysWb28Crld yearly. 🔗Hunter Link:https://t.co/PwOLy9qwQ4 👇Query HUNTER : https://t.co/q9rtuGgxk7=

    @HunterMapping

    27 Aug 2025

    3345 Impressions

    7 Retweets

    35 Likes

    10 Bookmarks

    0 Replies

    0 Quotes

Configurations