• News/
  • https://www.bleepingcomputer.com/news/security/over-28-200-citrix-instances-vulnerable-to-actively-exploited-rce-bug/

Over 28,000 Citrix devices vulnerable to new exploited RCE flaw

BleepingComputer
·
Bill Toulas
·
Published Aug 27, 2025
·
Updated

More than 28,200 Citrix instances are vulnerable to a critical remote code execution vulnerability tracked as CVE-2025-7775 that is already being exploited in the wild. The vulnerability affects NetScaler ADC and NetScaler Gateway and the vendor addressed it in updates released yesterday. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Citrix, the security issue has been exploited as a zero-day vulnerability. The versions affected by CVE-2025-7775 are 14.1 before 14.1-47.48, 13.1 before13.1-59.22, 13.1-FIPS/NDcPP before 13.1-37.241-FIPS/NDcPP, and 12.1-FIPS/NDcPP up to 12.1-55.330-FIPS/NDcPP. Citrix does not provide any mitigations or workarounds and urges admins to upgrade the firmware immediately. Internet scans conducted by the threat monitoring platform The Shadowserver Foundation soon after the flaw was disclosed show that there were more than 28,000 Citrix instances vulnerable to CVE-2025-7775. Most of the vulnerable instances are located in the United States (10,100), followed by Germany (4,300), the United Kingdom (1,400), the Netherlands (1,300), Switzerland (1,300), Australia (880), Canada (820), and France (600). Citrix did not share indicators of compromise associated with the exploitation activity. However, the vendor specifies that CVE-2025-7775 affects NetScaler when configured as a Gateway/AAA virtual server (VPN, ICA Proxy, CVPN, RDP Proxy), as LB virtual servers (HTTP/SSL/HTTP_QUIC) bound to IPv6 or DBS IPv6 services, or as...

Read full article

Affected Software

8 affected components
Citrix NetScaler ADC=14.1 before 14.1-47.48
Citrix NetScaler ADC=13.1 before 13.1-59.22
Citrix NetScaler ADC=13.1-FIPS/NDcPP before 13.1-37.241-FIPS/NDcPP
Citrix NetScaler ADC=12.1-FIPS/NDcPP up to 12.1-55.330-FIPS/NDcPP
Citrix NetScaler Gateway=14.1 before 14.1-47.48
Citrix NetScaler Gateway=13.1 before 13.1-59.22
Citrix NetScaler Gateway=13.1-FIPS/NDcPP before 13.1-37.241-FIPS/NDcPP
Citrix NetScaler Gateway=12.1-FIPS/NDcPP up to 12.1-55.330-FIPS/NDcPP
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in Citrix products affecting over 28,200 instances.

2

What security implications are discussed in the article?

The article highlights that the vulnerability, CVE-2025-7775, is actively being exploited in the wild, posing serious security risks.

3

What products or software are affected by the vulnerability?

The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway versions prior to specified release updates.

4

What versions of Citrix NetScaler are vulnerable according to the article?

Versions of Citrix NetScaler ADC and Gateway prior to 14.1-47.48, 13.1-59.22, and various FIPS/NDcPP versions are vulnerable.

5

What should users of affected Citrix products do?

Users of the affected Citrix products should immediately apply the necessary updates to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203