• News/
  • https://www.theregister.com/2025/07/07/citrixbleed_2_exploits/

CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands

The Register
·
Jessica Lyons
·
Published Jul 7, 2025
·
Updated

Multiple exploits are circulating for CVE-2025-5777, a critical bug in Citrix NetScaler ADC and NetScaler Gateway dubbed CitrixBleed 2, and security analysts are warning a "significant portion" of users still haven't patched. CVE-2025-5777 is a 9.3 CVSS-rated security flaw that allows remote, unauthenticated attackers to read sensitive info — such as session tokens — in memory from NetScaler devices configured as a gateway (such as a VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Miscreants can abuse this vuln to bypass multi-factor authentication (MFA), hijack user sessions, and access critical systems. The vendor disclosed and issued a patch for CVE-2025-5777 last month, but despite multiple reports indicating in-the-wild exploitation, plus proof-of-concept (POC) exploits, Citrix still hasn't responded to The Register's inquiries about the bug and the scope of the attacks. It all sounds very similar to an earlier flaw, dubbed CitrixBleed, which also allowed attackers to access a device's memory, find session tokens, and then use those to impersonate an authenticated user while bypassing MFA, despite Citrix's insistence that the two are not related. CitrixBleed was widely exploited by nation-state spies and ransomware groups. So CitrixBleed 2 is not a security hole that organizations want to leave open. However, a "significant portion of the Citrix NetScaler user base … have still not patched" CVE-2025-5777, according to watchTowr Labs researchers. On...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway

Frequently Asked Questions

1

What critical vulnerability is discussed in the article?

The article discusses CVE-2025-5777, a severe vulnerability known as CitrixBleed 2.

2

Which products are affected by the CitrixBleed 2 vulnerability?

The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.

3

What is the potential impact of the CitrixBleed 2 exploits?

The exploits can lead to significant security risks for users of the affected Citrix products.

4

What has prompted security researchers to raise alarms regarding CitrixBleed 2?

Multiple exploits for CitrixBleed 2 are circulating, prompting urgent warnings from security analysts.

5

How widespread is the vulnerability within the user base of Citrix products?

Security analysts indicate that a significant portion of users are still exposed to the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203