Three vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway—CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543—have prompted urgent patching and compromise checks. CVE-2025-5777, nicknamed CitrixBleed 2, is a memory-overread flaw that could expose session tokens and plaintext credentials. Horizon3.ai demonstrated an attack believed to exploit it through the /p/u/doAuthentication.do endpoint, leaking up to 127 bytes of adjacent memory. GreyNoise has observed malicious attempts targeting the flaw, but its reference does not establish successful exploitation. Citrix said it had not observed exploitation of CVE-2025-5777 at the time of the research, a position disputed by some security firms. Separately, Citrix acknowledged active exploitation of CVE-2025-6543, a memory-corruption vulnerability with potential control-flow or denial-of-service impact, which CISA added to its Known Exploited Vulnerabilities catalog.
The Dutch National Cyber Security Centre urged affected organizations to install Citrix updates promptly, investigate indicators of compromise, and terminate connections and sessions after patching so stolen sessions cannot preserve attacker access. The Netherlands Public Prosecution Service disconnected its systems from the internet after indications of abuse. Defenders should review logs for non-printable characters, investigate sessions used from multiple client IP addresses, and check for unauthorized accounts or configuration changes. Multiple NetScaler versions, including FIPS/NDcPP builds, are affected; organizations should verify their appliances against the relevant advisories. The NCSC warned that NetScaler and other internet-facing edge devices are attractive targets because their compromise can provide further access to organizational networks.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
GreyNoise created an activity tag classifying observed attempts to exploit CVE-2025-5777 as malicious. The reference does not identify victims or establish successful exploitation.
Citrix published an advisory for CVE-2025-6543 affecting NetScaler ADC and NetScaler Gateway. The memory corruption vulnerability could cause control-flow issues or denial of service.
Citrix published an advisory covering vulnerabilities in NetScaler ADC and NetScaler Gateway, including affected FIPS and NDcPP builds. CVE-2025-5777 is a memory overread vulnerability subsequently nicknamed CitrixBleed 2.
The Dutch NCSC urged affected organizations to install Citrix updates promptly and inspect systems for indicators of compromise. It explicitly recommended terminating connections and sessions after patching to prevent attackers from retaining access through stolen sessions.
The Netherlands Public Prosecution Service disconnected its systems from the internet in response to indications of abuse reported in the context of the NetScaler vulnerabilities.
Horizon3.ai described patch-diff analysis and a working exploit believed to target CVE-2025-5777 through the /p/u/doAuthentication.do endpoint. Testing demonstrated leakage of up to 127 bytes of adjacent memory, including session tokens and plaintext credentials.
Citrix Cloud Security Group stated that CVE-2025-5777 and the original CitrixBleed vulnerability, CVE-2023-4966, were unrelated. Citrix also said it had not observed CVE-2025-5777 exploitation in the wild, a position disputed by some security firms.
CISA added CVE-2025-6543 to its Known Exploited Vulnerabilities catalog, recognizing exploitation of the NetScaler vulnerability.
Citrix stated that it was aware of in-the-wild exploitation of the NetScaler memory corruption vulnerability CVE-2025-6543.
Citrix released security updates addressing CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543 in affected NetScaler products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcehorizon3.ai
Open sourceviz.greynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.