Skip to content
COOEY

EXPOSURES › CVE-2025-5777

CVE-2025-5777

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-07-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-5777 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedrce

Citrix NetScaler ADC and Gateway suffered an out-of-bounds read vulnerability linked to ransomware that was actively exploited in the wild.

The vulnerability allowed memory overreads when the NetScaler was configured as a Gateway or AAA virtual server, enabling attackers to execute arbitrary code. DIB organizations must patch immediately and monitor for ransomware activity, as this flaw was actively exploited in the wild and linked to ransomware campaigns.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized