CVE-2025-7775Active Exploitation(citrix / netscaler_application_delivery_controller)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-16); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-16: 1Mentions · 2026-06-08: 1Mentions · 2026-08-08: 1Mentions · 2026-09-13: 1Mentions · 2026-09-29: 1PoC Mentioned / Linked · 2026-09-13: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-08-08: 1Active Exploitation · 2026-09-13: 1Patch / Workaround · 2026-09-13: 1Technical Details · 2026-08-08: 1Technical Details · 2026-09-13: 103-1606-0808-0809-1309-29
Signal classification2 categories
Active Exploitation
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-161
General1
2026-06-081
Active Exploitation1
2026-08-081
Active Exploitation1
2026-09-131
Active Exploitation1
Full discourse5 posts
  • YourDailyCVE@YourDailyCVE
    Active Exploitation

    🚨 CVE-2026-19490 — Citrix NetScaler ADC & Gateway, authentication bypass (CVSS 9.3) What broke: On appliances used as a Gateway (SSL VPN, ICA Proxy, Clientless VPN, or RDP Proxy) or as an AAA virtual server, a request could take an alternate path and skip the login check (CWE-288). Unauthenticated, no user interaction. Who should care: Customer-managed NetScaler ADC/Gateway — 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, plus 14.1-FIPS before 14.1-73.32 FIPS and 13.1-FIPS/NDcPP before 13.1-37.277. Secure Private Access Hybrid instances on those builds are in scope. Citrix-managed cloud services and Adaptive Authentication were patched centrally. Preconditions aren’t one-size-fits-all: on 14.1-43.56+ (and matching later FIPS), you need a SAML action andGateway/AAA. On older 14.1 / older 13.1 / 13.1 FIPS, Gateway or AAA alone is enough. On 13.1-61.28+, Citrix’s trigger is a configured SAML action. Risk: This is the remote-access front door, not a dusty management port. There is no workaround in Citrix bulletin CTX696939. NetScaler Console Global Deny List signatures can reduce exposure on some mid-train builds; they are not the fix. Status: Actively exploited. Fix shipped 19 Aug with no known exploitation that day. Public PoC ~2 Sept, probes from 3 Sept, CISA KEV on 9 Sept, federal due date 12 Sept. Same “patch now, mass-scan next” arc as CitrixBleed, CitrixBleed 2, and CVE-2025-7775. Fix: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277. If you can’t patch today: restricting NSIP/mgmt to a dedicated VLAN does not close this hole. Inventory Gateway/AAA + add authentication samlAction and treat internet-facing boxes as emergency. Source: CTX696939 / CISA KEV #Citrix #NetScaler

    Post summary

    The post reports active exploitation of a high-severity Citrix NetScaler authentication bypass and cites CISA KEV. It provides affected versions, technical conditions, and fixed releases, while also noting a public PoC.

    10020323
    35 followersView on X
  • SecBriefs | Cybersecurity Decision Intelligence@SecBriefs

    Confirmed exploitation puts exposed NetScaler systems on an urgent clock. FortiGuard reports confirmed exploitation; CISA added CVE-2025-7775 to its KEV catalog. Patch exposed appliances; review Gateway and management-plane exposure. Get the brief → https://secbriefs.com/briefs/citrix-netscaler-rce-exploitation-confirmed-patch-priority-is-high https://t.co/1hfLQbATS0

    10001286
    14.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are exploiting CVE-2025-7775 for unauthenticated remote code execution on Citrix NetScaler devices. This critical memory overflow flaw enables immediate system compromise without credentials. Runtime segmentation helps contain post-compromise lateral movement in affected environments. #ZeroDay 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/citrix-netscaler-cve-2025-7775-2025-08-26

    Post summary

    The post reports that attackers are actively exploiting CVE-2025-7775 for unauthenticated remote code execution on Citrix NetScaler devices, citing a memory-overflow flaw, with no patch or PoC details provided.

    00010100
    1.9K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Citrix addressed three vulnerabilities in NetScaler ADC and NetScaler Gateway, including one that has been actively exploited in the wild. Citrix addressed three security flaws (CVE-2025-7775, CVE-2025-7776, CVE-2025-84... https://f.mtr.cool/ezxhxlxess

    Post summary

    Citrix released updates for three NetScaler vulnerabilities, with one being reported as actively exploited in the wild.

    0000040
    2.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    General

    TRC analysis shows attackers leveraging AI automation to reduce breach breakout times to mere seconds in 2026. After exploiting CVE-2025-7775, they used AI-driven tools for rapid lateral movement across cloud environments and automated privilege escalation through misconfigured IAM roles. Runtime segmentation helps contain such AI-accelerated breach chains. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/ai-enhanced-cyber-attacks-2026

    Post summary

    The post notes attackers using CVE‑2025‑7775 for rapid breach and lateral movement via AI, but it provides no proof‑of‑concept, exploit code, patch, or technical details about the vulnerability.

    00000110
    1.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more