Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Published:
Published:
Published:
https://www.theregister.com/2025/08/28/thousands_of_citrix_netscaler_boxes/
https://www.darkreading.com/vulnerabilities-threats/citrix-zero-day-under-active-attack
https://cyberscoop.com/citrix-netscaler-zero-day-exploited-august-2025/
https://www.securityweek.com/citrixbleed-2-flaw-poses-unacceptable-risk-cisa/
https://www.databreachtoday.com/attackers-now-scanning-extensively-for-citrix-bleed-2-a-28959
https://cyberscoop.com/citrixbleed2-exploits-spread/
https://thehackernews.com/2025/07/cisa-adds-citrix-netscaler-cve-2025.html
https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/
https://www.securityweek.com/exploits-technical-details-released-for-citrixbleed2-vulnerability/
https://www.databreachtoday.com/attackers-actively-exploit-citrix-bleed-2-vulnerability-a-28907
https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/
https://www.helpnetsecurity.com/2025/06/30/citrixbleed-2-might-be-actively-exploited-cve-2025-5777/
https://www.securityweek.com/evidence-suggests-exploitation-of-citrixbleed-2-vulnerability/
https://www.infosecurity-magazine.com/news/citrixbleed-2-vulnerability/
https://www.theregister.com/2025/06/25/citrix_netscaler_critical_bug_exploited/
https://thehackernews.com/2025/06/citrix-bleed-2-flaw-enables-token-theft.html
https://cyberscoop.com/citrix-zero-day-netscaler/
https://www.theregister.com/2025/06/24/critical_citrix_bug_citrixbleed/
https://doublepulsar.com/citrixbleed-2-electric-boogaloo-cve-2025-5777-c7f5e349d206
https://thehackernews.com/2025/04/critical-ivanti-flaw-actively-exploited.html
https://news.sophos.com/en-us/2025/04/02/2025-sophos-active-adversary-report/
https://www.ic3.gov/Media/News/2024/241010.pdf
https://services.google.com/fh/files/misc/m-trends-2024.pdf
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-attacks-exploits
https://www.secureworks.com/blog/lockbit-in-action
https://blog.talosintelligence.com/talos-ir-quarterly-report-q4-2023/
https://therecord.media/hhs-warns-of-citrix-bleed-bug
https://cyberplace.social/@GossiTheDog/111502145876827515
https://cybernews.com/news/yanfeng-ransomware-attack-claimed-qilin/
https://www.theregister.com/2025/08/12/major_outage_at_pennsylvania_attorney/
https://isc.sans.edu/diary/rss/30498
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a
Published: 2023-10-10
Updated: 2025-10-24
Named Vulnerability: CitrixBleedNamed Vulnerability: Citrix BleedKnown Exploited Vulnerability (KEV)
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Severity: High
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.94348
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Concern