Thousands of Citrix NetScaler appliances remain exposed to a trio of security flaws that the vendor patched this week, one of which is already being actively exploited in the wild. Fresh data from the Shadowserver Foundation shows that the number of vulnerable systems dropped from more than 28,000 on Wednesday to 13,000 on Thursday, suggesting that admins have been scrambling to patch. Even so, thousands remain open to attack, with more than 7,500 affected devices in the US, over 4,000 in Germany, and more than 1,200 in the UK. The findings underscore what security researchers have long warned: patch lag is leaving enterprises wide open, even when the vendor has already confirmed exploitation. Citrix's rushed-out fixes covered three bugs: CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424. CVE-2025-7775 – already dubbed CitrixBleed 3 by some – is the one to worry about: Citrix describes it as a memory overflow weakness that can be abused for remote code execution or denial-of-service, and it has been assigned a CVSS score of 9.2. Security researcher Kevin Beaumont stated that the flaw was being exploited as a pre-auth RCE to plant web shells on unpatched boxes. CISA has now added CVE-2025-7775 to its Known Exploited Vulnerabilities (KEV) catalogue, effectively making patching mandatory for US federal agencies. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the US cybersecurity agency warn...
Thousands of Citrix NetScaler boxes still sitting ducks despite patches
The Register
·Carly Page
·Published Aug 28, 2025
·Updated
Affected Software
1 affected component
Citrix NetScaler
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the ongoing security vulnerabilities in thousands of Citrix NetScaler boxes despite recent patches.
2
What security implications are discussed in the article?
The article highlights that some Citrix NetScaler appliances are still vulnerable to security flaws, one of which is being actively exploited.
3
What products are affected by the security flaws mentioned?
The affected product mentioned in the article is Citrix NetScaler.
4
How many Citrix NetScaler boxes are still exposed to vulnerabilities?
Thousands of Citrix NetScaler boxes remain exposed to critical vulnerabilities even after patches were released.
5
What organization provided data on the exposure of Citrix NetScaler appliances?
The Shadowserver Foundation provided data indicating the exposure of Citrix NetScaler appliances.