Citrix patched three critical vulnerabilities in on-premises NetScaler ADC and NetScaler Gateway appliances: CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424. Citrix reported active exploitation of CVE-2025-7775, which can cause denial of service or enable arbitrary code execution; the other flaws can also enable code execution and may allow unauthorized access.
The Dutch NCSC assessed the risk as High/High, citing widespread vulnerable deployments and the likelihood of large-scale exploitation. Citrix cloud services have been updated, while organizations operating affected on-premises appliances should urgently install Citrix fixes, apply vendor mitigations, monitor for suspicious activity, and use the NCSC's updated detection script to investigate potential compromise.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The Dutch NCSC updated its detection script to identify compromise associated with the newly disclosed Citrix NetScaler vulnerabilities.
Citrix released updates for CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424 affecting on-premises NetScaler ADC and NetScaler Gateway appliances, and patched its cloud solutions. Citrix reported that CVE-2025-7775 was being actively exploited.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.