Tech

CitrixBleed 2 flaws are officially here – so get patching or leave your systems at risk

Share
Share


  • Citrix disclosed patching a critical-severity bug in Citrix NetScaler ADC and Gateway instances
  • Independent researchers dub it “CitrixBleed 2” due to its similiarities to the 2023 flaw
  • Users are advised to patch up ASAP

Hackers are actively exploiting a critical-severity vulnerability in Citrix NetScaler ADC and Gateway instances to hijack user sessions and gain access to targeted environments, the company has revealed.

The bug is described as an insufficient input validation vulnerability that leads to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. It is tracked as CVE-2025-5777, and was given a severity score of 9.3/10 – critical.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Lenovo’s new AI Chromebook might be too smart for its own good, but it’s shockingly portable
Tech

Lenovo’s new AI Chromebook might be too smart for its own good, but it’s shockingly portable

MediaTek’s Kompanio Ultra makes a rare appearance, challenging the usual CPU suspects...

New hires are cybersecurity goldmines for hackers, and most companies don’t even realize they’re making it easy
Tech

New hires are cybersecurity goldmines for hackers, and most companies don’t even realize they’re making it easy

Most phishing incidents happen before new employees even understand how internal systems...

Analytical model evaluates performance of grant-free communication in densely populated IoT environment
Tech

Analytical model evaluates performance of grant-free communication in densely populated IoT environment

Credit: Pixabay/CC0 Public Domain Imagine a world where every smart device, from...