• News/
  • https://www.bleepingcomputer.com/news/security/citrix-bleed-2-exploited-weeks-before-pocs-as-citrix-denied-attacks/

Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks

BleepingComputer
·
Lawrence Abrams
·
Published Jul 17, 2025
·
Updated

A critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed "CitrixBleed 2," was actively exploited nearly two weeks before proof-of-concept (PoC) exploits were made public, despite Citrix stating that there was no evidence of attacks. GreyNoise has confirmed its honeypots detected targeted exploitation from IP addresses located in China on June 23, 2025. "GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept (PoC) was released on July 4," explains GreyNoise. "We created a tag on July 7 to track this activity. Because GreyNoise retroactively associates pre-tag traffic with new tags, prior exploitation attempts are now visible in the GreyNoise Visualizer." GreyNoise confirmed to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on July 9 that the flaw was actively exploited, causing the cyber agency to add it to its Known Exploited Vulnerabilities (KEV) catalog and giving federal agencies one day to patch the flaw. GreyNoise shared the exploit used in the June attacks with BleepingComputer and we can confirm that it is the one for Citrix Bleed 2, demonstrating that threat actors were actively exploiting it before the PoCs were released. Despite these early signs and repeated warnings from security researcher Kevin Beaumont, Citrix had still not acknowledged active exploitat...

Read full article

Affected Software

1 affected component
Citrix NetScaler
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article focuses on the active exploitation of a critical vulnerability in Citrix NetScaler, known as CVE-2025-5777, prior to the release of proof-of-concept exploits.

2

What security implications are discussed in the article?

The article discusses the serious security risks posed by the Citrix Bleed 2 vulnerability that was exploited before public knowledge, indicating that systems may have been compromised.

3

What products or software are affected by the Citrix Bleed 2 vulnerability?

The affected software highlighted in the article is Citrix NetScaler.

4

How did Citrix respond to reports of exploitation?

Citrix denied claims of active exploitation, despite evidence indicating that the vulnerability was being exploited weeks before the disclosure of proof-of-concept exploits.

5

What is the significance of the CVE-2025-5777 vulnerability?

CVE-2025-5777 is significant due to its critical rating and the fact that it was targeted by attackers even before its vulnerabilities were publicly confirmed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203