---
id: CVE-2025-5777
title: "Insufficient input validation leading to memory overread when the\_NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server"
summary: "Insufficient input validation leading to memory overread when the\_NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-125
  - CWE-908
  - CWE-457
vendor: citrix
product: netscaler_application_delivery_controller
affected:
  - 'netscaler_application_delivery_controller >= 12.1, < 12.1-55.328'
  - 'netscaler_application_delivery_controller >= 13.1, < 13.1-37.235'
  - 'netscaler_application_delivery_controller >= 13.1, < 13.1-58.32'
  - 'netscaler_application_delivery_controller >= 14.1, < 14.1-43.56'
  - 'netscaler_gateway >= 13.1, < 13.1-58.32'
  - 'netscaler_gateway >= 14.1, < 14.1-43.56'
patched:
  - netscaler_application_delivery_controller 14.1-43.56
  - netscaler_gateway 14.1-43.56
published: '2025-06-17'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5777'
references:
  - url: >-
      https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
    label: secure@citrix.com
  - url: 'https://citrixbleed.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://doublepulsar.com/citrixbleed-2-exploitation-started-mid-june-how-to-spot-it-f3106392aa71
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://reliaquest.com/blog/threat-spotlight-citrix-bleed-2-vulnerability-in-netscaler-adc-gateway-devices/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99972
epssPercentile: 0.99977
kev: true
kevDateAdded: '2025-07-10'
kevDueDate: '2025-07-11'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-04T05:36:13.009Z'
exploits:
  exploitdb: true
  github: 26
  githubRepos:
    - 'https://github.com/mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-'
    - 'https://github.com/RickGeex/CVE-2025-5777-CitrixBleed'
    - 'https://github.com/idobarel/CVE-2025-5777'
  nuclei:
    - CVE-2025-5777
  checkedAt: '2026-09-19T16:22:59.353Z'
---

## Overview

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

## Affected

- `netscaler_application_delivery_controller >= 12.1, < 12.1-55.328`
- `netscaler_application_delivery_controller >= 13.1, < 13.1-37.235`
- `netscaler_application_delivery_controller >= 13.1, < 13.1-58.32`
- `netscaler_application_delivery_controller >= 14.1, < 14.1-43.56`
- `netscaler_gateway >= 13.1, < 13.1-58.32`
- `netscaler_gateway >= 14.1, < 14.1-43.56`

## Remediation

Upgrade past the affected range:

- `netscaler_application_delivery_controller 14.1-43.56`
- `netscaler_gateway 14.1-43.56`
