• News/
  • https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/

CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch

BleepingComputer
·
Bill Toulas
·
Published Jul 11, 2025
·
Updated

The U.S. Cybersecurity & Infrastructure Security Agency has confirmed active exploitation of the CitrixBleed 2 vulnerability (CVE-2025-5777) in Citrix NetScaler ADC and Gateway and is giving federal agencies one day to apply fixes. Such a short deadline for installing the patches is unprecedented since CISA released the Known Exploited Vulnerabilities (KEV) catalog, showing the severity of the attacks exploiting the security issue. The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog yesterday, ordering federal agencies to implement mitigations by the end of today, June 11. CVE-2025-5777 is a critical memory safety vulnerability (out-of-bounds memory read) that gives an unauthenticated attacker access to restricted parts of the memory. The issue impacts NetScaler devices that are configured as a Gateway or an AAA virtual server, in versions prior to 14.1-43.56, 13.1-58.32, 13.1-37.235-FIPS/NDcPP, and 2.1-55.328-FIPS. Citrix addressed the vulnerability through updates released on June 17. A week later, security researcher Kevin Beaumont warned in a blog post about the flaw's potential for exploitation, its severity and repercussions if left unpatched. Beaumont called the flaw 'CitrixBleed 2' due to similarities with the infamous CitrixBleed vulnerability (CVE-2023-4966), which was extensively exploited in the wild by all types of cybercriminal actors. The first warning of CitrixBleed 2 being exploited came from ReliaQuest on June 27. On July 7, secur...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC<14.1-43.56, <13.1-58.32, <13.1-37.235-FIPS/NDcPP, <2.1-55.328-FIPS
Citrix NetScaler Gateway<14.1-43.56, <13.1-58.32, <13.1-37.235-FIPS/NDcPP, <2.1-55.328-FIPS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the active exploitation of the Citrix Bleed 2 vulnerability in Citrix NetScaler ADC and Gateway.

2

What security implications are discussed?

The article highlights that federal agencies are at risk due to the active exploitation of a critical vulnerability requiring urgent patching.

3

What products or software are affected?

The affected software includes Citrix NetScaler ADC and Gateway, specifically versions up to 14.1-43.56, 13.1-58.32, 13.1-37.235-FIPS/NDcPP, and 2.1-55.328-FIPS.

4

What recommendation is given to federal agencies?

Federal agencies are instructed to apply the available patches within one day due to the urgency of the vulnerability.

5

What is the identifier for the Citrix Bleed 2 vulnerability?

The Citrix Bleed 2 vulnerability is identified by the CVE number CVE-2025-5777.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203