LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-7775: Citrix NetScaler Memory Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 26, 2025
CVSS 9.2 · Critical⚠ Actively exploited (CISA KEV)
9.2
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Aug 28, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-7775 to its Known Exploited Vulnerabilities catalog on Aug 26, 2025, with a federal patch deadline of Aug 28, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

CVE-2025-7775 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway. It can allow remote code execution or denial of service if successfully abused. Because these appliances often sit at the network edge handling authentication, load balancing, and remote access, a successful attack can give an adversary a foothold into internal systems or disrupt critical connectivity. Public detail is limited to the CISA summary and the CWE classification; teams must confirm exact impact, versions, and fixes against the vendor advisory.

How it works

The flaw is classified as CWE-119, improper restriction of operations within the bounds of a memory buffer. In products of this class, an attacker who can reach a vulnerable network service may send crafted input that causes the process to write or read past the intended buffer limits. That overflow can corrupt adjacent memory, crash the process (denial of service), or, under the right conditions, allow the attacker to redirect execution flow and run arbitrary code with the privileges of the NetScaler process.

No public exploit mechanics, specific packets, or proof-of-concept details are supplied in the available facts. Defenders should treat any unauthenticated or lightly authenticated interface on the appliance as a potential attack surface and assume remote reachability is sufficient for exploitation attempts. Confirm the precise attack vector and preconditions only from the official Citrix advisory.

Am I affected? How to find it in your systems

Citrix NetScaler ADC and NetScaler Gateway appliances commonly appear as physical or virtual appliances in DMZs, as reverse proxies, SSL VPN gateways, or application delivery controllers. Inventory every instance by querying configuration management databases, network discovery tools, and cloud asset inventories for hostnames, management IPs, or license strings that identify NetScaler.

If you run NetScaler in a cloud or managed service, also follow the applicable BOD 22-01 guidance referenced by CISA.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions for CVE-2025-7775 as soon as they are available and tested in your environment. CISA’s required action is to apply mitigations per vendor instructions, follow BOD 22-01 for cloud services, or discontinue use of the product if mitigations cannot be applied.

Document the change and retain evidence of the version upgrade for compliance and audit purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface with compensating controls appropriate to a memory-corruption vulnerability on a network appliance.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full appliance compromise and subsequent lateral movement or data theft. Known ransomware use is not documented for CVE-2025-7775, but that does not eliminate the possibility of other post-exploitation activity. Review logs for signs of unauthorized access, reset any credentials that may have been handled by the appliance, and examine connected systems for secondary compromise. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · NetScaler
WeaknessCWE-119
CVSS base score9.2 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedAug 26, 2025
Added to CISA KEVAug 26, 2025
Federal patch deadlineAug 28, 2025
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities