Multiple exploits are circulating for CVE-2025-5777, a critical bug in Citrix NetScaler ADC and NetScaler Gateway dubbed CitrixBleed 2, and security analysts are warning a "significant portion" of users still haven't patched. CVE-2025-5777 is a 9.3 CVSS-rated security flaw that allows remote, unauthenticated attackers to read sensitive info — such as session tokens — in memory from NetScaler devices configured as a gateway (such as a VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Miscreants can abuse this vuln to bypass multi-factor authentication (MFA), hijack user sessions, and access critical systems. The vendor disclosed and issued a patch for CVE-2025-5777 last month, but despite multiple reports indicating in-the-wild exploitation, plus proof-of-concept (POC) exploits, Citrix still hasn't responded to The Register's inquiries about the bug and the scope of the attacks. It all sounds very similar to an earlier flaw, dubbed CitrixBleed, which also allowed attackers to access a device's memory, find session tokens, and then use those to impersonate an authenticated user while bypassing MFA, despite Citrix's insistence that the two are not related. CitrixBleed was widely exploited by nation-state spies and ransomware groups. So CitrixBleed 2 is not a security hole that organizations want to leave open. However, a "significant portion of the Citrix NetScaler user base … have still not patched" CVE-2025-5777, according to watchTowr Labs researchers. On...
CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands
The Register
·Jessica Lyons
·Published Jul 7, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Frequently Asked Questions
1
What critical vulnerability is discussed in the article?
The article discusses CVE-2025-5777, a severe vulnerability known as CitrixBleed 2.
2
Which products are affected by the CitrixBleed 2 vulnerability?
The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.
3
What is the potential impact of the CitrixBleed 2 exploits?
The exploits can lead to significant security risks for users of the affected Citrix products.
4
What has prompted security researchers to raise alarms regarding CitrixBleed 2?
Multiple exploits for CitrixBleed 2 are circulating, prompting urgent warnings from security analysts.
5
How widespread is the vulnerability within the user base of Citrix products?
Security analysts indicate that a significant portion of users are still exposed to the vulnerability.