Monday, June 30, 2025
HomeNewsCitrixBleed 2 flaws are officially here - so get patching or leave...

CitrixBleed 2 flaws are officially here – so get patching or leave your systems at risk

CitrixBleed 2 flaws are officially here – so get patching or leave your systems at risk


  • Citrix disclosed patching a critical-severity bug in Citrix NetScaler ADC and Gateway instances
  • Independent researchers dub it “CitrixBleed 2” due to its similiarities to the 2023 flaw
  • Users are advised to patch up ASAP

Hackers are actively exploiting a critical-severity vulnerability in Citrix NetScaler ADC and Gateway instances to hijack user sessions and gain access to targeted environments, the company has revealed.

The bug is described as an insufficient input validation vulnerability that leads to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. It is tracked as CVE-2025-5777, and was given a severity score of 9.3/10 – critical.

Source

Author

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular