CitrixBleed 2 flaws are officially here – so get patching or leave your systems at risk


- Citrix disclosed patching a critical-severity bug in Citrix NetScaler ADC and Gateway instances
- Independent researchers dub it “CitrixBleed 2” due to its similiarities to the 2023 flaw
- Users are advised to patch up ASAP
Hackers are actively exploiting a critical-severity vulnerability in Citrix NetScaler ADC and Gateway instances to hijack user sessions and gain access to targeted environments, the company has revealed.
The bug is described as an insufficient input validation vulnerability that leads to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. It is tracked as CVE-2025-5777, and was given a severity score of 9.3/10 – critical.
The flaw affects Citrix NetScaler ADC and Gateway device versions 14.1 and before 47.46, and from 13.1 and before 59.19.
CitrixBleed 2
According to security researchers ReliaQuest, the vulnerability is already being abused in the wild to grant attackers initial access.
“Unlike session cookies, which are often tied to short-lived browser sessions, session tokens are typically used in broader authentication frameworks, such as API calls or persistent application sessions,” the researchers explained.
As well as publicly disclosing the vulnerability, Citrix is also offering a fix, and urging users to apply it as soon as possible.
At the same time, independent analyst Kevin Beaumont says the bug bears a resemblance to CitrixBleed, one of the most serious Citrix vulnerabilities discovered in recent years.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
It was also a critical-severity flaw that was widely exploited in late 2023, when different threat actors targeted government agencies, banks, healthcare providers. Among the abusers was LockBit, one of the most dangerous ransomware operators in existence.
Due to the similarities, Beaumont dubbed the flaw “CitrixBleed 2”.
At roughly the same time, Citrix disclosed addressing two additional flaws: a high-severity access control issue, and a memory overflow vulnerability.
The former has a severity score of 8.7, and impacts versions from 14.1 and before 43.56 and from 13.1 and before 58.32. The latter, with a 9.2 severity score, is tracked as CVE-2025-6543, and leads to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway.
You might also like
Citrix disclosed patching a critical-severity bug in Citrix NetScaler ADC and Gateway instances Independent researchers dub it “CitrixBleed 2” due to its similiarities to the 2023 flaw Users are advised to patch up ASAP Hackers are actively exploiting a critical-severity vulnerability in Citrix NetScaler ADC and Gateway instances to hijack…
Recent Posts
- ‘It’s obvious that users are frustrated’: consumer rights group accuses Microsoft of not providing a ‘viable solution’ for Windows 10 users who can’t upgrade to Windows 11
- Threads now has DMs
- Nintendo revealed the Super Mario Odyssey team made Donkey Kong Bananza
- Fortnite next season release date and what to expect from Chapter 6 Season 4
- The Best Hot Dog Cookers for All-American Hot Dogging (2025)
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020