H-ISAC TLP White Threat Bulletin PoC Exploits Available for Citrix NetScaler ADC and NetScaler Gateway Flaw CVE-2025-5777
Proof-of-Concept (PoC) exploits for a critical vulnerability, tracked as CVE-2025-5777 and dubbed CitrixBleed2, affecting Citrix NetScaler ADC and Gateway devices are publicly available.
Security researchers have confirmed that the security flaw’s exploit complexity is low and can lead to the compromise of user session tokens. Successful exploitation allows threat actors to access memory contents by delivering specially crafted POST requests during login attempts.
Despite Citrix advising that there is no evidence to suggest CVE-2025-5777 is actively being exploited, security researchers have opposing information that indicates otherwise.
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: