H-ISAC TLP White Vulnerability Report Citrix Discloses a Trio of Vulnerabilities Affecting NetScaler ADC and NetScaler Gateway

On August 26, 2025, Citrix released a security bulletin (CTX694938) to address three critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products: CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424.

The most severe of these, CVE-2025-7775, is an actively exploited memory overflow flaw that can lead to remote code execution (RCE) and/or denial of service (DoS). The other two vulnerabilities allow for DoS and improper access control, respectively. Citrix strongly urges all users with affected, user-managed appliances to update to the recommended builds immediately to mitigate these critical risks.

Health-ISAC provides this information to increase situational awareness, encourage users to assess their level of risk to these vulnerabilities, and apply patches to affected instances.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272