Critical Citrix RCE Flaw Hits Thousands of Devices
More than 28,000 Citrix NetScaler instances are exposed to a zero-day remote code execution vulnerability actively exploited in the wild, affecting multiple countries including the U.S., Germany, and the U.K.
Citrix NetScaler Flaws Expose SAML and User Sessions
Critical and high-severity vulnerabilities in Citrix NetScaler ADC and Gateway could allow attackers to read sensitive memory or cause session mix-ups, affecting on-prem deployments.
Citrix released CVE‑2026‑3055 fixes for NetScaler ADC and Gateway appliances, preventing unauthenticated out-of-bounds memory reads when used as SAML Identity Providers.
CitrixBleed 2: New Critical Bug May Already Be Under Attack
Security experts are warning that a new NetScaler flaw—dubbed CitrixBleed 2—could already be in hackers’ hands. It lets attackers steal live session tokens and bypass login protections without ever needing a password.
Researchers from ReliaQuest observed suspicious signs that CVE-2025-5777, an unauthenticated memory leak vulnerability in NetScaler ADC and Gateway, may already be exploited in the wild—despite Citrix claiming no confirmed abuse. Like the infamous 2023 CitrixBleed, it allows attackers to hijack sessions and evade all authentication. Analysts spotted reused sessions from consumer VPNs and Active Directory probes, hinting at reconnaissance post-access.
Sources: Help Net Security | NetScaler | ReliaQuest