A critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed "CitrixBleed 2," was actively exploited nearly two weeks before proof-of-concept (PoC) exploits were made public, despite Citrix stating that there was no evidence of attacks. GreyNoise has confirmed its honeypots detected targeted exploitation from IP addresses located in China on June 23, 2025. "GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept (PoC) was released on July 4," explains GreyNoise. "We created a tag on July 7 to track this activity. Because GreyNoise retroactively associates pre-tag traffic with new tags, prior exploitation attempts are now visible in the GreyNoise Visualizer." GreyNoise confirmed to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on July 9 that the flaw was actively exploited, causing the cyber agency to add it to its Known Exploited Vulnerabilities (KEV) catalog and giving federal agencies one day to patch the flaw. GreyNoise shared the exploit used in the June attacks with BleepingComputer and we can confirm that it is the one for Citrix Bleed 2, demonstrating that threat actors were actively exploiting it before the PoCs were released. Despite these early signs and repeated warnings from security researcher Kevin Beaumont, Citrix had still not acknowledged active exploitat...
Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article focuses on the active exploitation of a critical vulnerability in Citrix NetScaler, known as CVE-2025-5777, prior to the release of proof-of-concept exploits.
What security implications are discussed in the article?
The article discusses the serious security risks posed by the Citrix Bleed 2 vulnerability that was exploited before public knowledge, indicating that systems may have been compromised.
What products or software are affected by the Citrix Bleed 2 vulnerability?
The affected software highlighted in the article is Citrix NetScaler.
How did Citrix respond to reports of exploitation?
Citrix denied claims of active exploitation, despite evidence indicating that the vulnerability was being exploited weeks before the disclosure of proof-of-concept exploits.
What is the significance of the CVE-2025-5777 vulnerability?
CVE-2025-5777 is significant due to its critical rating and the fact that it was targeted by attackers even before its vulnerabilities were publicly confirmed.