Over 1,200 Citrix NetScaler ADC and NetScaler Gateway appliances exposed online are unpatched against a critical vulnerability believed to be actively exploited, allowing threat actors to bypass authentication by hijacking user sessions. Tracked as CVE-2025-5777 and referred to as Citrix Bleed 2, this out-of-bounds memory read vulnerability results from insufficient input validation, enabling unauthenticated attackers to access restricted memory regions. A similar Citrix security flaw, dubbed "CitrixBleed," was exploited in ransomware attacks and breaches targeting governments in 2023 to hack NetScaler devices and move laterally across compromised networks. Successfully exploiting CVE-2025-5777 could allow threat actors to steal session tokens, credentials, and other sensitive data from public-facing gateways and virtual servers, enabling them to hijack user sessions and bypass multi-factor authentication (MFA). In a June 17 advisory, Citrix warned customers to terminate all active ICA and PCoIP sessions after upgrading all their NetScaler appliances to a patched version to block potential attacks. On Monday, security analysts from the internet security nonprofit Shadowserver Foundation have discovered over the weekend that 2,100 appliances were still vulnerable to CVE-2025-5777 attacks. While Citrix has yet to confirm that this security flaw is being exploited in the wild, saying that "currently, there is no evidence to suggest exploitation of CVE-2025-5777," cybersecurity ...
Over 1,200 Citrix servers unpatched against critical auth bypass flaw
BleepingComputer
·Sergiu Gatlan
·Published Jun 30, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses over 1,200 unpatched Citrix NetScaler servers vulnerable to a critical authentication bypass flaw.
2
What security implications are discussed in the article?
The discussed vulnerability allows threat actors to bypass user authentication and hijack sessions.
3
What products or software are affected by the vulnerability?
The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.
4
What is the identifier assigned to this critical vulnerability?
This vulnerability is tracked as CVE-2025-5777 and is referred to as Citrix Bleed 2.
5
Is this vulnerability believed to be actively exploited?
Yes, the vulnerability is believed to be actively exploited by threat actors.