• News/
  • https://www.theregister.com/2025/08/28/thousands_of_citrix_netscaler_boxes/

Thousands of Citrix NetScaler boxes still sitting ducks despite patches

The Register
·
Carly Page
·
Published Aug 28, 2025
·
Updated

Thousands of Citrix NetScaler appliances remain exposed to a trio of security flaws that the vendor patched this week, one of which is already being actively exploited in the wild. Fresh data from the Shadowserver Foundation shows that the number of vulnerable systems dropped from more than 28,000 on Wednesday to 13,000 on Thursday, suggesting that admins have been scrambling to patch. Even so, thousands remain open to attack, with more than 7,500 affected devices in the US, over 4,000 in Germany, and more than 1,200 in the UK. The findings underscore what security researchers have long warned: patch lag is leaving enterprises wide open, even when the vendor has already confirmed exploitation. Citrix's rushed-out fixes covered three bugs: CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424. CVE-2025-7775 – already dubbed CitrixBleed 3 by some – is the one to worry about: Citrix describes it as a memory overflow weakness that can be abused for remote code execution or denial-of-service, and it has been assigned a CVSS score of 9.2. Security researcher Kevin Beaumont stated that the flaw was being exploited as a pre-auth RCE to plant web shells on unpatched boxes. CISA has now added CVE-2025-7775 to its Known Exploited Vulnerabilities (KEV) catalogue, effectively making patching mandatory for US federal agencies. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the US cybersecurity agency warn...

Read full article

Affected Software

1 affected component
Citrix NetScaler
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the ongoing security vulnerabilities in thousands of Citrix NetScaler boxes despite recent patches.

2

What security implications are discussed in the article?

The article highlights that some Citrix NetScaler appliances are still vulnerable to security flaws, one of which is being actively exploited.

3

What products are affected by the security flaws mentioned?

The affected product mentioned in the article is Citrix NetScaler.

4

How many Citrix NetScaler boxes are still exposed to vulnerabilities?

Thousands of Citrix NetScaler boxes remain exposed to critical vulnerabilities even after patches were released.

5

What organization provided data on the exposure of Citrix NetScaler appliances?

The Shadowserver Foundation provided data indicating the exposure of Citrix NetScaler appliances.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203