A critical NetScaler ADC and Gateway vulnerability dubbed "Citrix Bleed 2" (CVE-2025-5777) is now likely exploited in attacks, according to cybersecurity firm ReliaQuest, seeing an increase in suspicious sessions on Citrix devices. Citrix Bleed 2, named by cybersecurity researcher Kevin Beaumont due to its similarity to the original Citrix Bleed (CVE-2023-4966), is an out-of-bounds memory read vulnerability that allows unauthenticated attackers to access portions of memory that should typically be inaccessible. This could allow attackers to steal session tokens, credentials, and other sensitive data from public-facing gateways and virtual servers, enabling them to hijack user sessions and bypass multi-factor authentication (MFA). Citrix's advisor also confirms this risk, warning users to end all ICA and PCoIP sessions after installing security updates to block access to any hijacked sessions. The flaw, tracked as CVE-2025-5777, was addressed by Citrix on June 17, 2025, with no reports of active exploitation. However, Beaumont warned about the high likelihood of exploitation earlier this week. The researcher's worries now seem justified, as ReliaQuest says with medium confidence that CVE-2025-5777 is already being leveraged in targeted attacks. "While no public exploitation of CVE-2025-5777, dubbed "Citrix Bleed 2," has been reported, ReliaQuest assesses with medium confidence that attackers are actively exploiting this vulnerability to gain initial access to targeted environ...
Citrix Bleed 2 flaw now believed to be exploited in attacks
BleepingComputer
·Bill Toulas
·Published Jun 27, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC
Citrix Gateway
Frequently Asked Questions
1
What vulnerability is discussed in the article?
The article discusses a critical vulnerability in Citrix products known as 'Citrix Bleed 2' or CVE-2025-5777.
2
What products are affected by the Citrix Bleed 2 flaw?
The affected products include Citrix NetScaler ADC and Citrix Gateway.
3
How is the Citrix Bleed 2 flaw being exploited?
The article notes that there has been an increase in suspicious sessions on Citrix devices, indicating active exploitation.
4
Who identified the Citrix Bleed 2 flaw?
The flaw was named by cybersecurity researcher Kevin Beaumont.
5
What is the current status of the Citrix Bleed 2 vulnerability?
The vulnerability is now believed to be actively exploited in attacks.