Dutch investigators found malicious webshells on Citrix NetScaler ADC and NetScaler Gateway appliances at multiple organizations following exploitation of critical 2025 NetScaler vulnerabilities. The affected flaws include CVE-2025-5777—an unauthenticated, remotely exploitable out-of-bounds read issue widely known as CitrixBleed 2—along with CVE-2025-5349 and CVE-2025-6543; public proof-of-concept code for CVE-2025-5777 increased the likelihood of broad exploitation.
The Dutch NCSC urged organizations to immediately apply Citrix updates, investigate appliances for signs of compromise, and terminate active ICA, PCoIP, RDP, AAA, and load-balancing persistent sessions after patching. It also released forensic scripts and updated indicators of compromise for reviewing NetScaler coredumps and full appliance images, as researchers warned that exposed and unremediated devices may already have been compromised.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
The NCSC released two forensic scripts to inspect NetScaler coredumps and complete appliance images for compromise. The scripts incorporated indicators of compromise identified through recent NCSC forensic investigations.
Proof-of-concept exploit code for the unauthenticated, remotely exploitable CVE-2025-5777 out-of-bounds read flaw was published, raising the risk of large-scale exploitation.
Citrix remediated CVE-2025-5777 and CVE-2025-5349 in NetScaler ADC and NetScaler Gateway on or before 18 June 2025.
The NCSC determined that one or more advanced threat actors exploited Citrix NetScaler CVE-2025-6543 as a zero-day from at least early May 2025, successfully attacking multiple critical organizations in the Netherlands. Forensic investigations found that the attackers actively erased traces of their activity.
The Dutch Public Prosecution Service (Openbaar Ministerie) disconnected systems from the internet following indications that Citrix NetScaler vulnerabilities had been abused. The reference does not specify when the disconnection occurred.
Citrix released security updates for the critical NetScaler ADC and NetScaler Gateway memory-management vulnerability CVE-2025-6543. The NCSC warned that the flaw had been exploited on unpatched systems and urged organizations to install the updates promptly.
During investigations at multiple Dutch organizations, the NCSC found NetScaler appliances vulnerable to CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543, including malicious webshells that could provide remote access. The NCSC contacted organizations with possible exploitation, while the Digital Trust Center sought to identify and notify additional affected businesses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcedoublepulsar.com
Open sourcencsc.nl
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.