Updated The US Cybersecurity and Infrastructure Security Agency has added its weighty name to the list of parties agreeing that CVE-2025-5777, dubbed CitrixBleed 2 by one researcher, has been under exploitation and abused to hijack user sessions. On Thursday, CISA added the critical security flaw to its catalog of Known Exploited Vulnerabilities. The agency cited "evidence of active exploitation" in its alert. "These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA warned. The bug, a 9.3 CVSS-rated security flaw that allows remote, unauthenticated attackers to read sensitive info — such as session tokens — in memory from NetScaler devices configured as a gateway (such as a VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, looked bad from the start. Citrix disclosed and issued a fix for CVE-2025-5777 back on June 17. Shortly thereafter, bug hunters started sounding the alarm on how bad things could get if customers didn't patch immediately. Security maven Kevin Beaumont dubbed the new vulnerability "CitrixBleed 2" because it closely resembled an earlier critical hole in the same NetScale products, CVE-2023-4966, that allowed attackers to access a device's memory, find session tokens, and then use those to impersonate an authenticated user while bypassing multi-factor authentication. By early July, researchers had published at least two working exploits that showed ho...
CISA agrees that CitrixBleed 2 is under exploit
The Register
·Jessica Lyons
·Published Jul 10, 2025
·Updated
Affected Software
1 affected component
Citrix NetScaler
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of CitrixBleed 2, a vulnerability affecting Citrix NetScaler, confirmed by CISA.
2
What security implications are discussed in the article?
The article highlights the risk of session hijacking due to the exploitation of the CVE-2025-5777 vulnerability.
3
Who has confirmed the exploitation of CitrixBleed 2?
The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed the exploitation of CitrixBleed 2.
4
What products or software are affected by the CitrixBleed 2 vulnerability?
The affected software is Citrix NetScaler.
5
What is the specific vulnerability identifier mentioned in the article?
The specific vulnerability identifier mentioned is CVE-2025-5777.