Tag: Citrix NetScaler ADC

Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now
News

Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now

Proof-of-concept (PoC) attacks for a severe Citrix NetScaler vulnerability, known as CitrixBleed2 and tagged as CVE-2025-5777, have been made public by researchers. The weakness is easily exploitable and has the potential to successfully steal user session tokens. By submitting erroneous POST requests during login attempts, attackers can obtain memory contents using the CitrixBleed 2 vulnerability, which impacts Citrix NetScaler ADC and Gateway devices. Because it closely mimics the original CitrixBleed (CVE-2023-4966) hole from 2023, which was used by ransomware gangs and in government assaults to take over user sessions and compromise networks, this significant flaw is called CitrixBleed2. The vulnerability can be exploited by providing an erroneous login request, where the log...