CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog Amid Active Exploits Targeting Enterprises

Published:

spot_img

Significant Vulnerability in Citrix NetScaler ADC and Gateway: What You Need to Know

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a serious security flaw affecting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog. This move confirms that the vulnerability, identified as CVE-2025-5777, has been actively exploited in the field.

Details of the Vulnerability: CVE-2025-5777

CVE-2025-5777 has a CVSS score of 9.3, highlighting its severity. The flaw arises from insufficient input validation, allowing attackers to bypass authentication mechanisms when the appliance is configured as a Gateway or AAA virtual server. Dubbed Citrix Bleed 2, this vulnerability shares characteristics with a previous issue known as Citrix Bleed (CVE-2023-4966).

CISA describes this vulnerability as an out-of-bounds read that results from the inadequate validation of inputs. When exploited, it can lead to memory overreads if the NetScaler is set up to function as a Gateway (encompassing VPN virtual servers, ICA Proxy, CVPN, and RDP Proxy) or AAA virtual server.

Evidence of Exploitation

While Citrix has been slow to update its advisories regarding real-world exploitation, security researcher Kevin Beaumont has indicated that attacks utilizing this vulnerability may have started as early as mid-June. Beaumont notes that one IP address involved in these attacks has been associated with RansomHub ransomware activities, signaling a serious potential threat.

Recent data from GreyNoise has tracked malicious activities stemming from ten distinct IP addresses across various countries, such as Bulgaria, the United States, China, Egypt, and Finland. The primary targets of these exploitation attempts include regions like the United States, France, Germany, India, and Italy.

Additional Vulnerabilities and Risks

CVE-2025-5777 isn’t the only flaw causing concern. Another critical vulnerability in the same product, identified as CVE-2025-6543 and possessing a CVSS score of 9.2, has also been confirmed as under active exploitation. This suggests a troubling trend in the security landscape for Citrix products, with multiple vulnerabilities being targeted simultaneously.

The term "Citrix Bleed" underscores the nature of the vulnerability: repeated attempts to exploit it can result in leakage of sensitive stack memory. This leads to what is described as a "drastic increase in vulnerability scanner traffic," especially following the public disclosure of exploit details.

Implications for Organizations

Exploitations of these vulnerabilities are particularly concerning due to their potential ramifications. Affected devices frequently act as centralized entry points for enterprise networks, which makes them prime targets for cybercriminals. An unauthorized access breach could expose sensitive information, including session tokens and other vital data, thereby granting attackers entry to internal applications and networks.

In environments lacking adequate internal segmentation—especially hybrid IT setups—this type of lateral movement can transform an initial breach into comprehensive network access, posing a significant threat to the organization’s security.

Recommended Mitigation Steps

To combat these vulnerabilities, organizations are urged to upgrade to the patched versions specified in Citrix’s advisory from June 17. This includes versions 14.1-43.56 and later. Post-upgrade, it is essential to terminate all active sessions, particularly those authenticated via the affected methods, to invalidate any potentially compromised tokens.

Furthermore, administrators should closely examine logs for suspicious activities directed at authentication endpoints. Notably, requests to endpoints like /p/u/doAuthentication.do should be scrutinized for unexpected XML data such as <initialvalue>. Given the nature of the issue—a memory overread—it’s crucial to note that traditional malware detection methods may not suffice; the focus should primarily be on preventing token hijacks and session replays.

Continued Monitoring

The landscape of cybersecurity is constantly evolving, and the risks associated with vulnerabilities like CVE-2025-5777 highlight the importance of ongoing vigilance. Organizations must ensure they stay updated on the latest security advisories and implement effective measures to safeguard their systems against emerging threats. Regular audits, patch management, and proactive monitoring are vital components of a robust security strategy.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...