Multiple severe vulnerabilities in Citrix ADC and NetScaler Gateway exposed organizations to unauthenticated compromise, including remote code execution in CVE-2019-19781 and CVE-2023-3519, as well as memory disclosure in CVE-2023-4966 (CitrixBleed) and the later CVE-2025-5777 variant. Public reporting showed that CVE-2019-19781 could be exploited through crafted HTTP requests that abused directory traversal and template parsing to execute commands on vulnerable appliances, while research on CVE-2023-3519 examined another critical path to code execution on internet-facing Citrix infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Cybersecurity Dive reported that Citrix NetScaler products were confirmed to be under exploitation. This represents a new public confirmation of active abuse affecting NetScaler systems beyond the previously documented 2025 CitrixBleed 2 reporting.
Akamai published mitigation guidance for CVE-2025-5777, referred to as CitrixBleed 2, affecting NetScaler memory disclosure. The publication reflects public technical guidance on defending against the flaw.
Reporting indicated that CVE-2025-5777, dubbed CitrixBleed 2, was already being exploited in the wild while many organizations were slow to patch affected NetScaler systems. The development marked an escalation from vulnerability awareness to observed malicious abuse.
Computer Weekly reported that CVE-2025-5777, known as CitrixBleed 2, was believed to be under active attack. This marks public reporting that the vulnerability had moved from disclosure concern to suspected in-the-wild exploitation.
Citrix published a NetScaler ADC and NetScaler Gateway security bulletin covering CVE-2025-5349 and CVE-2025-5777. The advisory marked the vendor's official disclosure and guidance for the vulnerabilities affecting NetScaler products.
The U.S. Department of Health and Human Services warned the healthcare sector about CitrixBleed attacks after hospital outages were reported. The alert marked a sector-specific government response highlighting operational impact on healthcare organizations.
CISA said the CitrixBleed vulnerability, CVE-2023-4966, was being actively exploited by both nation-state and financially motivated threat actors. The warning marked an official U.S. government alert highlighting the breadth and seriousness of ongoing exploitation.
Following public reporting on CitrixBleed (CVE-2023-4966), defenders were urged to rapidly patch affected NetScaler systems and investigate for signs of compromise as concern grew over active malicious exploitation. The development marked an operational response phase beyond the initial technical reporting on the flaw.
Unit 42 published a threat brief on CVE-2023-4966, commonly known as CitrixBleed, documenting the vulnerability and associated threat activity. This marks public reporting on the issue by early November 2023.
Cloud Software Group disclosed and released fixed builds for CVE-2023-3519, a critical unauthenticated remote code execution flaw affecting customer-managed NetScaler ADC and NetScaler Gateway deployments configured as a gateway or AAA virtual server. The company said no workaround was available beyond upgrading and warned the vulnerability was being exploited in targeted attacks.
Assetnote published research analyzing CVE-2023-3519 in Citrix ADC and NetScaler Gateway, adding technical detail to understanding of the vulnerability. The reference indicates public disclosure of analysis by July 2023.
Citrix released patches for CVE-2019-19781 in late January 2020 after initially providing only mitigation guidance. The fixes addressed the widely exploited remote code execution risk on vulnerable appliances.
By early 2020, public exploit code for CVE-2019-19781 became available and FireEye reported threat actors were actively exploiting vulnerable Citrix systems to install malware, including NOTROBIN. The exploitation chain involved directory traversal and template parsing to achieve unauthenticated remote code execution.
Citrix disclosed the authentication bypass vulnerability CVE-2019-19781 affecting Citrix ADC, Gateway, NetScaler, and SD-WAN WANOP products. The company initially advised customers to apply mitigations before patches were available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
cybersecuritydive.com
Open sourcetrustedsec.com
Open sourceakamai.com
Open sourcetheregister.com
Open sourcehackingtutorials.org
Open sourcefireeye.com
Open sourceisc.sans.edu
Open sourcefr.tenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.