CitrixBleed 2 exploits are now in the wild, so patch now
- CitrixBleed 2 was discovered in late June 2025
- The majority of instances have not yet been patched
- Security researchers are warning the bug is likely being exploited already
CitrixBleed 2, a vulnerability in Citrix NetScaler ADC and NetScaler Gateway, is now being actively exploited in the wild, multiple researchers have warned.
Security researchers recently found a critical-severity vulnerability in these instances which could allow threat actors to hijack user sessions and gain access to targeted environments.
The flaw, described as an insufficient input validation vulnerability that leads to memory overread, is tracked as CVE-2025-5777, and affects device versions 14.1 and before 47.46, and from 13.1 and before 59.19. Given its similarity to a previous Citrix vulnerability called CitrixBleed, security researchers dubbed it CitrixBleed 2.
(No) evidence of abuse
A patch was made available soon after, but apparently, the majority of instances have not yet been patched, and threat actors are taking advantage of that fact. Multiple security researchers, including ReliaQuest, watchTowr, and Horizon3.ai, have warned users of ongoing exploitation campaigns.
The Register notes watchTowr Labs found a, “significant portion of the Citrix NetScaler user base” had not yet patched against CitrixBleed 2, urging everyone to do so since the bug is “trivial” to exploit.
“Previously, we stated that we had no intention to release this vulnerability analysis,” the researchers said. However, “minimal” information sharing about the flaw “puts these users in a tough position when determining if they need to sound an internal alarm.”
Soon afterwards, Horizon3.ai said “by now threat actors are likely to be including it in their toolkits as well.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
At the same time, Citrix is giving out mixed signals whether or not the bugs are actually being exploited in the wild. The company is redirecting all media inquiries to a blog post discussing the matter, in which it says “Currently, there is no evidence to suggest exploitation of CVE-2025-5777.”
However, in the FAQ of the same blog post, it also said “immediate installation of the recommended updates is critically important due to the identified severity of this vulnerability and evidence of active exploitation.” It is left somewhat vague if this answer relates to CitrixBleed 2, or a different vulnerability.
Finally, elsewhere in the FAQ, it says “We are currently unaware of any evidence of exploitation for CVE-2025-5349 or CVE-2025-5777.”
We’d advise everyone to patch up, just to be on the safe side, especially since CitrixBleed was being abused by nation-states in highly targeted attacks.
You might also like
CitrixBleed 2 was discovered in late June 2025 The majority of instances have not yet been patched Security researchers are warning the bug is likely being exploited already CitrixBleed 2, a vulnerability in Citrix NetScaler ADC and NetScaler Gateway, is now being actively exploited in the wild, multiple researchers have…
Recent Posts
- LG Promo Codes and Coupons for June 2026
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023