CitrixBleed 2: New Critical Bug May Already Be Under Attack
Security experts are warning that a new NetScaler flaw—dubbed CitrixBleed 2—could already be in hackers’ hands. It lets attackers steal live session tokens and bypass login protections without ever needing a password.
Researchers from ReliaQuest observed suspicious signs that CVE-2025-5777, an unauthenticated memory leak vulnerability in NetScaler ADC and Gateway, may already be exploited in the wild—despite Citrix claiming no confirmed abuse. Like the infamous 2023 CitrixBleed, it allows attackers to hijack sessions and evade all authentication. Analysts spotted reused sessions from consumer VPNs and Active Directory probes, hinting at reconnaissance post-access.
Sources: Help Net Security | NetScaler | ReliaQuest