• News/
  • https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/

CISA agrees that CitrixBleed 2 is under exploit

The Register
·
Jessica Lyons
·
Published Jul 10, 2025
·
Updated

Updated The US Cybersecurity and Infrastructure Security Agency has added its weighty name to the list of parties agreeing that CVE-2025-5777, dubbed CitrixBleed 2 by one researcher, has been under exploitation and abused to hijack user sessions. On Thursday, CISA added the critical security flaw to its catalog of Known Exploited Vulnerabilities. The agency cited "evidence of active exploitation" in its alert. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA warned. The bug, a 9.3 CVSS-rated security flaw that allows remote, unauthenticated attackers to read sensitive info — such as session tokens — in memory from NetScaler devices configured as a gateway (such as a VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, looked bad from the start. Citrix disclosed and issued a fix for CVE-2025-5777 back on June 17. Shortly thereafter, bug hunters started sounding the alarm on how bad things could get if customers didn't patch immediately. Security maven Kevin Beaumont dubbed the new vulnerability "CitrixBleed 2" because it closely resembled an earlier critical hole in the same NetScale products, CVE-2023-4966, that allowed attackers to access a device's memory, find session tokens, and then use those to impersonate an authenticated user while bypassing multi-factor authentication. By early July, researchers had published at least two working exploits that showed ho...

Read full article

Affected Software

1 affected component
Citrix NetScaler

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of CitrixBleed 2, a vulnerability affecting Citrix NetScaler, confirmed by CISA.

2

What security implications are discussed in the article?

The article highlights the risk of session hijacking due to the exploitation of the CVE-2025-5777 vulnerability.

3

Who has confirmed the exploitation of CitrixBleed 2?

The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed the exploitation of CitrixBleed 2.

4

What products or software are affected by the CitrixBleed 2 vulnerability?

The affected software is Citrix NetScaler.

5

What is the specific vulnerability identifier mentioned in the article?

The specific vulnerability identifier mentioned is CVE-2025-5777.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203