The U.S. Cybersecurity & Infrastructure Security Agency has confirmed active exploitation of the CitrixBleed 2 vulnerability (CVE-2025-5777) in Citrix NetScaler ADC and Gateway and is giving federal agencies one day to apply fixes. Such a short deadline for installing the patches is unprecedented since CISA released the Known Exploited Vulnerabilities (KEV) catalog, showing the severity of the attacks exploiting the security issue. The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog yesterday, ordering federal agencies to implement mitigations by the end of today, June 11. CVE-2025-5777 is a critical memory safety vulnerability (out-of-bounds memory read) that gives an unauthenticated attacker access to restricted parts of the memory. The issue impacts NetScaler devices that are configured as a Gateway or an AAA virtual server, in versions prior to 14.1-43.56, 13.1-58.32, 13.1-37.235-FIPS/NDcPP, and 2.1-55.328-FIPS. Citrix addressed the vulnerability through updates released on June 17. A week later, security researcher Kevin Beaumont warned in a blog post about the flaw's potential for exploitation, its severity and repercussions if left unpatched. Beaumont called the flaw 'CitrixBleed 2' due to similarities with the infamous CitrixBleed vulnerability (CVE-2023-4966), which was extensively exploited in the wild by all types of cybercriminal actors. The first warning of CitrixBleed 2 being exploited came from ReliaQuest on June 27. On July 7, secur...
CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch
BleepingComputer
·Published Jul 11, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC<14.1-43.56, <13.1-58.32, <13.1-37.235-FIPS/NDcPP, <2.1-55.328-FIPS
Citrix NetScaler Gateway<14.1-43.56, <13.1-58.32, <13.1-37.235-FIPS/NDcPP, <2.1-55.328-FIPS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the active exploitation of the CitrixBleed 2 vulnerability in Citrix products and the urgent patching requirements set by CISA.
2
What security implications are discussed in the article?
The article highlights the risk posed by the CitrixBleed 2 vulnerability being actively exploited, which poses a threat to federal agencies using affected Citrix products.
3
What products or software are affected by the CitrixBleed 2 vulnerability?
The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.
4
What is the severity of the CitrixBleed 2 vulnerability?
The severity is significant as it has been confirmed to be actively exploited, leading to CISA's urgent response.
5
How quickly does CISA expect agencies to respond to the CitrixBleed 2 vulnerability?
CISA has given federal agencies only one day to apply the necessary patches.