criticalKEV
CVE-2025-5777
CitrixBleed 2: out-of-bounds memory disclosure on the login endpoint leaks session tokens, replayed to hijack sessions and bypass MFA (CVSS 9.3)
- Severity
- critical
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 94% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added to CISA KEV 2025-07-10; Imperva observed ~11.5M exploitation attempts, 40% against financial services. Deliberately NOT version-gated: Citrix fixes this at build level (14.1-43.56 / 13.1-58.32) while this row's version regex only captures major.minor, so an `lt` would flag patched 14.1 devices - a false positive. Advisory until a build-level version source exists.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →