• News/
  • https://www.theregister.com/2025/08/26/citrix_patches_trio_of_netscaler/

Citrix patches trio of NetScaler bugs – after attackers beat them to it

The Register
·
Carly Page
·
Published Aug 26, 2025
·
Updated

Citrix has pushed out fixes for three fresh NetScaler holes – and yes, they've already been used in the wild before the vendor got around to patching. The flaws, tracked as CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424, affect NetScaler ADC and NetScaler Gateway appliances. Security researcher Kevin Beaumont confirmed that they've been used as zero-days, meaning attackers were inside before the vendor's patch cycle caught up. He singled out CVE-2025-7775 as "the main problem" – a pre-auth remote code execution bug that's being abused to drop webshells and backdoor appliances. Citrix itself describes it as a memory overflow bug that can be abused for remote code execution or denial of service, and it's been slapped with a CVSS score of 9.2 Beaumont added that affected organizations will likely need to carry out incident response, given the risk of persistent access after exploitation. In a security bulletin on Tuesday, Citrix admitted that CVE-2025-7775 has already been exploited on unpatched appliances. The company hasn't answered our questions about how widespread the attacks are, leaving the scale of the break-ins a mystery for now. The bugs arrive on the back of a bruising summer for Citrix. The vendor has already dealt with CVE-2025-6543, a memory overflow flaw rated 9.2 on the CVSS scale, which turned into a live exploit before fixes were widely applied. And there's CVE-2025-5777, dubbed CitrixBleed 2 by Beaumont, a memory overread echo of the infamous 2023 CitrixBleed...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Citrix releasing patches for three vulnerabilities found in their NetScaler products.

2

What security implications are discussed?

The vulnerabilities had been exploited by attackers before Citrix issued the patches, raising concerns about the effectiveness of their security protocols.

3

What products or software are affected?

The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.

4

What are the CVE identifiers associated with the vulnerabilities?

The vulnerabilities are tracked as CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424.

5

What is the response of Citrix to these vulnerabilities?

Citrix has released fixes for the identified NetScaler holes to mitigate the associated security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203