CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
Description
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
In plain language
AI Act nowCVE-2025-5777 is a Citrix NetScaler Gateway/AAA weakness that lets attackers read extra data from memory, and because it’s already being exploited in the wild, a typical small business using these devices should act urgently to patch or mitigate.
What to do
- Check whether your Citrix NetScaler ADC / NetScaler Gateway is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.
- Update to the fixed Citrix release your IT/security team specifies (do not delay patching).
- If you can’t patch immediately, ask your IT person what temporary mitigations Citrix recommends for your exact configuration and ensure the device is not exposed beyond what’s necessary.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and Moreen·The Hacker News· Roundup ai-ml
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentialsen·The Hacker News· Exploited netscaler anubis
- CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)en·watchTowr Labs· Research NetScaler ADC network-edge
- INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023en·The Hacker News· Exploited Acronis INC
- INC Ransomware Thrives by Mastering the Basicsen·Dark Reading· Research Acronis INC
- Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)en·watchTowr Labs· Exploited NetScaler ADC info-disclosure
- The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)en·watchTowr Labs· Research NetScaler ADC info-disclosure
- Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101)en·watchTowr Labs· Research Citrix NetScaler info-disclosure
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-5777 and every CVE in our database. Create a free account — no credit card required.
Create Free Account