Citrix has pushed out fixes for three fresh NetScaler holes – and yes, they've already been used in the wild before the vendor got around to patching. The flaws, tracked as CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424, affect NetScaler ADC and NetScaler Gateway appliances. Security researcher Kevin Beaumont confirmed that they've been used as zero-days, meaning attackers were inside before the vendor's patch cycle caught up. He singled out CVE-2025-7775 as "the main problem" – a pre-auth remote code execution bug that's being abused to drop webshells and backdoor appliances. Citrix itself describes it as a memory overflow bug that can be abused for remote code execution or denial of service, and it's been slapped with a CVSS score of 9.2 Beaumont added that affected organizations will likely need to carry out incident response, given the risk of persistent access after exploitation. In a security bulletin on Tuesday, Citrix admitted that CVE-2025-7775 has already been exploited on unpatched appliances. The company hasn't answered our questions about how widespread the attacks are, leaving the scale of the break-ins a mystery for now. The bugs arrive on the back of a bruising summer for Citrix. The vendor has already dealt with CVE-2025-6543, a memory overflow flaw rated 9.2 on the CVSS scale, which turned into a live exploit before fixes were widely applied. And there's CVE-2025-5777, dubbed CitrixBleed 2 by Beaumont, a memory overread echo of the infamous 2023 CitrixBleed...
Citrix patches trio of NetScaler bugs – after attackers beat them to it
The Register
·Carly Page
·Published Aug 26, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Citrix releasing patches for three vulnerabilities found in their NetScaler products.
2
What security implications are discussed?
The vulnerabilities had been exploited by attackers before Citrix issued the patches, raising concerns about the effectiveness of their security protocols.
3
What products or software are affected?
The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.
4
What are the CVE identifiers associated with the vulnerabilities?
The vulnerabilities are tracked as CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424.
5
What is the response of Citrix to these vulnerabilities?
Citrix has released fixes for the identified NetScaler holes to mitigate the associated security risks.