Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix multiple vulnerabilities, led by CVE-2025-5777, a critical out-of-bounds read flaw dubbed "Citrix Bleed 2" because of its similarity to the 2023 Citrix Bleed bug. The vulnerability affects NetScaler deployments used as a Gateway or virtual AAA server and can let a remote unauthenticated attacker read memory, steal sensitive data such as credentials and configuration, hijack sessions, bypass MFA, and potentially gain broader control of affected systems. Citrix and third-party reporting also highlighted CVE-2025-6543, a denial-of-service flaw reported as actively exploited, and CVE-2025-5349, a high-severity improper access control issue in the NetScaler Management Interface that could allow unauthorized access from the same network segment.
Security researchers reported signs consistent with real-world exploitation of CVE-2025-5777 for initial access, including hijacked Citrix web sessions reused across multiple IP addresses, LDAP-based Active Directory reconnaissance, and use of ADExplorer64.exe against multiple domain controllers. Citrix urged administrators to upgrade affected versions immediately, including NetScaler ADC and Gateway 14.1 before 14.1-43.56, 13.1 before 13.1-58.32, 13.1-FIPS/NDcPP before 13.1-37.235-FIPS/NDcPP, and 12.1-FIPS before 12.1-55.328-FIPS, while noting older 12.1 and 13.0 branches are end-of-life. The company also recommended terminating active ICA and PCoIP sessions after patching HA pairs or clusters and monitoring for anomalous HTTP activity associated with session theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK stated that CVE-2025-5777, also called Citrix Bleed 2, is actively exploited and can enable out-of-bounds memory reads, credential and configuration theft, MFA bypass, and possible full system compromise in affected NetScaler deployments. The notice also highlighted Citrix's patch for CVE-2025-5349 in the NetScaler Management Interface.
ReliaQuest reported indicators consistent with real-world exploitation of CVE-2025-5777 for initial access, despite no public reporting cited in the reference. Observed activity included hijacked Citrix web sessions, session reuse across multiple IPs, LDAP-based Active Directory reconnaissance, and use of ADExplorer64.exe across multiple domain controllers.
On 2025-06-17, Citrix issued an advisory and released updates for NetScaler ADC and Gateway vulnerabilities including CVE-2025-5777 and CVE-2025-6543. The guidance included upgrading to fixed versions and terminating active ICA/PCoIP sessions after patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.