An advanced threat actor exploited the critical vulnerabilities “Citrix Bleed 2" (CVE-2025-5777) in NetScaler ADC and Gateway, and CVE-2025-20337 affecting Cisco Identity Service Engine (ISE) as zero-days to deploy custom malware. Amazon’s threat intelligence team, analyzing “MadPot” honeypot data, found that hackers leveraged the two security issues before the security issues were disclosed publicly and patches became available. “Our Amazon MadPot honeypot service detected exploitation attempts for the Citrix Bleed Two vulnerability (CVE-2025-5777) prior to public disclosure, indicating a threat actor had been exploiting the vulnerability as a zero-day,” explains Amazon. “Through further investigation of the same threat exploiting the Citrix vulnerability, Amazon Threat Intelligence identified and shared with Cisco an anomalous payload targeting a previously undocumented endpoint in Cisco ISE that used vulnerable deserialization logic.” Citrix Bleed 2 is a NetScaler ADC and Gateway out-of-bounds memory read problem that the vendor published fixes for in late June. Although the vendor needed a longer period to confirm that the flaw was leveraged in attacks, despite multiple third-party reports claiming it was used in attacks, exploits became available in early July, and CISA tagged it as exploited. The flaw in ISE (CVE-2025-20337), with a maximum severity score, was published on July 17, when Cisco warned that it could be exploited to let an unauthenticated attacker store ma...
Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
BleepingComputer
·Bill Toulas
·Published Nov 12, 2025
·Updated
Affected Software
3 affected components
Citrix NetScaler ADC
Citrix Gateway
Cisco Identity Service Engine
Frequently Asked Questions
1
What vulnerabilities are discussed in the article?
The article discusses the 'Citrix Bleed 2' vulnerability (CVE-2025-5777) in NetScaler ADC and Gateway, and CVE-2025-20337 affecting Cisco Identity Service Engine.
2
What type of attacks were executed using these vulnerabilities?
Hackers exploited these vulnerabilities in zero-day attacks to deploy custom malware.
3
Which products are affected by these security flaws?
The affected products include Citrix NetScaler ADC, Citrix Gateway, and Cisco Identity Service Engine.
4
Who are the threat actors mentioned in the article?
The article refers to the attackers as advanced threat actors.
5
What is the significance of these vulnerabilities in security terms?
These critical vulnerabilities pose serious risks as they allow unauthorized access and exploitation of network infrastructure.