The U.S. Cybersecurity & Infrastructure Security Agency has confirmed active exploitation of the CitrixBleed 2 vulnerability (CVE-2025-5777) in Citrix NetScaler ADC and Gateway and is giving federal agencies one day to apply fixes. Such a short deadline for installing the patches is unprecedented since CISA released the Known Exploited Vulnerabilities (KEV) catalog, showing the severity of the attacks exploiting the security issue. The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog yesterday, ordering federal agencies to implement mitigations by the end of today, June 11. CVE-2025-5777 is a critical memory safety vulnerability (out-of-bounds memory read) that gives an unauthenticated attacker access to restricted parts of the memory. The issue impacts NetScaler devices that are configured as a Gateway or an AAA virtual server, in versions prior to 14.1-43.56, 13.1-58.32, 13.1-37.235-FIPS/NDcPP, and 2.1-55.328-FIPS. Citrix addressed the vulnerability through updates released on June 17. A week later, security researcher Kevin Beaumont warned in a blog post about the flaw's potential for exploitation, its severity and repercussions if left unpatched. Beaumont called the flaw 'CitrixBleed 2' due to similarities with the infamous CitrixBleed vulnerability (CVE-2023-4966), which was extensively exploited in the wild by all types of cybercriminal actors. The first warning of CitrixBleed 2 being exploited came from ReliaQuest on June 27. On July 7, secur...
CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch
BleepingComputer
·Bill Toulas
·Published Jul 11, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC<14.1-43.56, <13.1-58.32, <13.1-37.235-FIPS/NDcPP, <2.1-55.328-FIPS
Citrix NetScaler Gateway<14.1-43.56, <13.1-58.32, <13.1-37.235-FIPS/NDcPP, <2.1-55.328-FIPS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the active exploitation of the Citrix Bleed 2 vulnerability in Citrix NetScaler ADC and Gateway.
2
What security implications are discussed?
The article highlights that federal agencies are at risk due to the active exploitation of a critical vulnerability requiring urgent patching.
3
What products or software are affected?
The affected software includes Citrix NetScaler ADC and Gateway, specifically versions up to 14.1-43.56, 13.1-58.32, 13.1-37.235-FIPS/NDcPP, and 2.1-55.328-FIPS.
4
What recommendation is given to federal agencies?
Federal agencies are instructed to apply the available patches within one day due to the urgency of the vulnerability.
5
What is the identifier for the Citrix Bleed 2 vulnerability?
The Citrix Bleed 2 vulnerability is identified by the CVE number CVE-2025-5777.