Attackers continued to target Citrix NetScaler ADC and NetScaler Gateway systems vulnerable to CVE-2025-5777, a critical flaw also dubbed Citrix Bleed 2 that can let unauthenticated attackers obtain sensitive information and hijack user sessions. The vulnerability affects NetScaler deployments configured as described in Citrix’s security bulletin, and public advisories warned that exploitation could also enable arbitrary file reads, broader information disclosure, and denial of service on exposed appliances.
SOC telemetry showed exploitation attempts persisted well beyond initial disclosure, with detections recorded from mid-July through September 2025 rather than a brief spike. One observed pattern used a POST request to /p/u/doAuthentication.do with an unusually long User-Agent header to retrieve memory data, while much of the attack traffic was traced to infrastructure in the United States and France. Citrix and national defenders urged organizations to identify affected NetScaler ADC and Gateway versions and apply the vendor’s fixed releases immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC observed numerous intermittent attacks targeting CVE-2025-5777 from July through September 2025, indicating continued exploitation rather than a brief spike. Most observed attack traffic during this period originated from the United States and France.
MBSD-SOC reported its first detections of exploitation attempts against CVE-2025-5777. The observed activity included POST requests to /p/u/doAuthentication.do using an unusually long User-Agent header to retrieve memory information.
The Citrix NetScaler ADC and NetScaler Gateway vulnerability CVE-2025-5777 was publicly disclosed. The flaw, later referred to in the reporting as "Citrix Bleed 2," can allow unauthenticated attackers to obtain sensitive information and hijack sessions.
CSIRT Italia reported new vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway that could enable arbitrary file reads, sensitive information disclosure, and denial of service. The notice said only systems configured as described in the vendor bulletin are vulnerable and recommended updating to fixed versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcembsd.jp
Open sourcecve.mitre.org
Open sourcesupport.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.