Attackers continued to target Citrix NetScaler ADC and NetScaler Gateway systems vulnerable to CVE-2025-5777, a critical flaw also dubbed Citrix Bleed 2 that can let unauthenticated attackers obtain sensitive information and hijack user sessions. The vulnerability affects NetScaler deployments configured as described in Citrix’s security bulletin, and public advisories warned that exploitation could also enable arbitrary file reads, broader information disclosure, and denial of service on exposed appliances.
SOC telemetry showed exploitation attempts persisted well beyond initial disclosure, with detections recorded from mid-July through September 2025 rather than a brief spike. One observed pattern used a POST request to /p/u/doAuthentication.do with an unusually long User-Agent header to retrieve memory data, while much of the attack traffic was traced to infrastructure in the United States and France. Citrix and national defenders urged organizations to identify affected NetScaler ADC and Gateway versions and apply the vendor’s fixed releases immediately.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC observed numerous intermittent attacks targeting CVE-2025-5777 from July through September 2025, indicating continued exploitation rather than a brief spike. Most observed attack traffic during this period originated from the United States and France.
MBSD-SOC reported its first detections of exploitation attempts against CVE-2025-5777. The observed activity included POST requests to /p/u/doAuthentication.do using an unusually long User-Agent header to retrieve memory information.
The Citrix NetScaler ADC and NetScaler Gateway vulnerability CVE-2025-5777 was publicly disclosed. The flaw, later referred to in the reporting as "Citrix Bleed 2," can allow unauthenticated attackers to obtain sensitive information and hijack sessions.
On June 18, 2025, Mnemonic published an advisory describing CVE-2025-5777 as a critical memory overread flaw in NetScaler ADC and NetScaler Gateway and warning it could expose sensitive information to unauthenticated attackers. The advisory said Citrix had not seen active exploitation at that time and recommended upgrading to fixed builds, terminating active ICA and PCoIP sessions after patching, and restricting management interface access.
CSIRT Italia reported new vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway that could enable arbitrary file reads, sensitive information disclosure, and denial of service. The notice said only systems configured as described in the vendor bulletin are vulnerable and recommended updating to fixed versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcedocs.netscaler.com
Open sourcembsd.jp
Open sourcemnemonic.io
Open sourcecve.mitre.org
Open sourcesupport.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.