If your staff reach their desktops or apps through a Citrix login page, that page is probably running on a NetScaler Gateway. Attackers know that too, and 2025 and 2026 have given its owners very little rest.
The one that got a nickname was CVE-2025-5777, which researchers called "Citrix Bleed 2" after the 2023 Citrix Bleed bug it resembled. It let anyone on the internet read chunks of the appliance's memory without logging in. Memory on a busy gateway holds session tokens, and a stolen session token is a way in that skips the password and the MFA prompt.
By October 2026 it was far from the newest problem. Read the section on September 2026 before anything else.
How it works
NetScaler (the product formerly called Citrix ADC and Citrix Gateway) sits in front of your Citrix or other internal apps and handles the login. CVE-2025-5777 was an input validation bug that caused a memory overread when the appliance was set up as a Gateway (VPN virtual server, ICA Proxy, CVPN or RDP Proxy) or an AAA virtual server. That covers most real-world remote access setups.
An attacker sends a malformed login request, and the appliance answers with bytes it should never have sent. Repeat it enough and some of those bytes are valid session tokens. Plug one in and you are that user, already signed in.
That's why patching alone isn't the whole fix. The patch stops new leaks. It does nothing about a token that was stolen yesterday and is still valid.
The timeline
- 17 June 2025: Citrix publishes the fix for CVE-2025-5777 and a management interface flaw, CVE-2025-5349.
- 25 June 2025: a separate flaw, CVE-2025-6543, is fixed. Citrix says it had already seen it exploited.
- 10 July 2025: CISA adds CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalogue, with a one-day deadline for US federal agencies.
- 26 August 2025: CVE-2025-7775, a memory overflow leading to remote code execution, is fixed and already exploited.
- 2026: CVE-2026-3055 (March, affecting appliances set up as a SAML identity provider) and CVE-2026-19490 (an authentication bypass, published August) both end up on the KEV list.
- 27 September 2026: Citrix publishes eight more CVEs, and says two of them are being exploited. More on that below.
Are you affected?
You are in scope if you run NetScaler ADC or NetScaler Gateway yourself, on hardware (MPX or SDX) or as a virtual appliance (VPX). The Citrix-managed cloud services are patched by Citrix.
For Citrix Bleed 2, the fixed builds were 14.1-43.56, 13.1-58.32, 13.1-37.235 FIPS and NDcPP, and 12.1-55.328 FIPS. Versions 12.1 and 13.0 are end of life, are vulnerable, and will not be fixed. If you still have one, that is the real problem to solve.
Anything older than the September 2026 builds below is now vulnerable to something actively exploited, so in practice the question is simply: are you on the current build?
September 2026: patch again, now
On 27 September 2026 Citrix published a bulletin covering CVE-2026-88771 to CVE-2026-88778 and said exploits of CVE-2026-88771 and CVE-2026-88772 had been observed. CISA added both to its KEV list the same day.
- CVE-2026-88771 lets an unauthenticated attacker run commands. Citrix says every NetScaler ADC and Gateway deployment is affected, including default configurations.
- CVE-2026-88772 is a memory overflow that can lead to code execution where DTLS is enabled, which it is by default on a VPN virtual server.
The fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS and NDcPP, or later. This one is not a "next maintenance window" job.
How to fix it
- Upgrade every appliance to the current fixed build. In a high availability pair or cluster, upgrade all nodes.
- Then kill the sessions. For CVE-2025-5777, Citrix's advice was to run
kill icaconnection -allandkill pcoipConnection -allonce every node is on the fixed build. Users will need to log in again. Better them than someone holding their token. - Keep the management interface (NSIP) off the internet. CVE-2025-5349 (June 2025) and CVE-2025-8424 (August 2025) were both flaws in the management interface.
- Send logs off the box. Citrix notes that local logs may only go back a few days, which is useless for an investigation that starts a month later.
If you think it already happened
For Citrix Bleed 2, Citrix suggests two checks. Search the syslog for "Authentication is rejected for" lines from AAA containing non-ASCII bytes, a sign of exploit attempts. And look at VPN session records where the client IP changes during a single session, which can point to a stolen token (or just someone moving from office Wi-Fi to home, so check before panicking).
If there are signs of compromise, Citrix's own recovery guide is thorough and worth following in order:
- Preserve evidence first: snapshot a VPX, keep the remote logs, generate a support bundle.
- Take the appliance off the network.
- Change every secret stored on it (LDAP service accounts, RADIUS secrets, API keys, SNMP communities), reset passwords for users who signed in through it, and revoke its certificates.
- Rebuild or reimage, upgrade the firmware, then restore a configuration backup you know predates the compromise.
- Investigate the systems the NetScaler talked to, especially authentication servers.
Report it through ReportCyber at cyber.gov.au or call 1300 CYBER1 (1300 292 371). If personal information may have been accessed, check whether the Notifiable Data Breaches scheme applies. Our FortiGate guide walks through the same thinking for firewalls: a patched edge device can still be carrying yesterday's compromise.
Where Geidi fits
Our cyber security services are aligned to the Essential Eight, ISO/IEC 27001 and SMB1001, and backed by a 24/7 security operations centre. If you'd like to talk about your remote access setup, get in touch.
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-5349 and CVE-2025-5777 (CTX693420) (opens in a new tab)
- NetScaler blog: Critical security updates for CVE-2025-6543 and CVE-2025-5777 (opens in a new tab)
- NetScaler blog: Evaluating NetScaler logs for indicators of attempted exploitation of CVE-2025-5777 (15 July 2025) (opens in a new tab)
- Citrix: Security Bulletin for CVE-2025-6543 (CTX694788) (opens in a new tab)
- Citrix: Security Bulletin for CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424 (CTX694938) (opens in a new tab)
- Citrix: Security Bulletin for CVE-2026-3055 and CVE-2026-4368 (CTX696300) (opens in a new tab)
- Citrix: Security Bulletin for CVE-2026-19489 and CVE-2026-19490 (CTX696939) (opens in a new tab)
- Citrix: Security Bulletin for CVE-2026-88771 through CVE-2026-88778 (CTX697096) (opens in a new tab)
- Citrix: Steps to take if NetScaler ADC is suspected to be compromised (CTX694799) (opens in a new tab)
- CISA: Known Exploited Vulnerabilities catalogue (opens in a new tab)
- NVD: CVE-2025-5777 (opens in a new tab)
- ASD's ACSC: Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway products (opens in a new tab)
- ASD's ACSC: Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products (opens in a new tab)
