CitrixBleed 2 is the name researcher Kevin Beaumont gave to CVE-2025-5777, a memory overread in Citrix NetScaler ADC and NetScaler Gateway that Citrix patched on 17 June 2025. A crafted login request to a NetScaler configured as a gateway or AAA server makes the appliance return fragments of its memory, and those fragments can include live session tokens. With a stolen token, an attacker can take over a VPN or Citrix session that has already passed MFA. On 26 June 2025 ReliaQuest reported, with medium confidence, that the flaw was being exploited to hijack sessions, while Citrix said there was no evidence of exploitation. Public exploits followed in early July, CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 10 July, and SecurityWeek reported at least 100 organisations hacked by 18 July. The sessions stolen were overwhelmingly those of human users, so we list this incident as a human-identity breach, as we did its 2023 predecessor.
Key takeaways
- CVE-2025-5777 (CVSS 9.3) lets an unauthenticated attacker read leftover memory from a NetScaler gateway by sending a login request with a malformed field, according to Citrix and watchTowr Labs.
- Horizon3.ai showed the leaked memory can contain legitimate user session tokens, plaintext credentials and even a session token for the appliance's built-in "nsroot" administrator.
- ReliaQuest saw hijacked Citrix sessions authenticated without user interaction, followed by Active Directory reconnaissance. SecurityWeek later reported at least 100 organisations hacked and Imperva counted close to 12 million attack attempts by 11 July.
- Citrix initially said there was no evidence of exploitation. CISA listed the flaw as actively exploited on 10 July 2025, and Citrix updated its blog on 11 July.
- The identity lesson: a session token is a bearer credential that has already passed MFA, so patching alone is not enough; every session that existed before the patch has to be killed.
At a glance
| Organisations | Citrix (Cloud Software Group), maker of NetScaler ADC and NetScaler Gateway; customers running unpatched gateways, with at least 100 organisations reported hacked across education, finance, government, legal, technology and telecoms |
|---|---|
| When | Patched 17 June 2025; exploitation from about 20 June 2025 according to Kevin Beaumont; first public report of exploitation 26 June 2025 (ReliaQuest); CISA KEV listing 10 July 2025 |
| Attacker | Unattributed. Multiple actors scanning and exploiting at scale; GreyNoise reported early attempts from IP addresses geolocated in China |
| Entry point | Unauthenticated memory overread in the NetScaler gateway login handler (CVE-2025-5777) |
| Identities abused | VPN and Citrix user session tokens that had already passed MFA; in Horizon3.ai's research, plaintext login credentials and an "nsroot" administrator session token |
| Impact | Session hijacking and MFA bypass on corporate gateways, followed by Active Directory reconnaissance in at least one observed case; at least 100 organisations reported hacked |
| Category | Human identity (not listed as an NHI or AI agent breach). Incident class: human-identity breach (actively exploited flaw used to steal user session tokens) |
What happened
NetScaler ADC and NetScaler Gateway sit at the edge of many corporate networks, handling VPN, Citrix virtual desktop and single sign-on traffic. On 17 June 2025 Citrix published security bulletin CTX693420 for CVE-2025-5777, which it described as "insufficient input validation leading to memory overread". It affects appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server. Citrix told customers to upgrade to 14.1-43.56, 13.1-58.32 or the matching FIPS builds and then to terminate all active ICA and PCoIP sessions. Kevin Beaumont named the flaw CitrixBleed 2 because it resembled CitrixBleed (CVE-2023-4966), which ransomware groups used in 2023 to hijack sessions at Boeing and others.
On 26 June ReliaQuest said it assessed "with medium confidence" that attackers were already exploiting the flaw. It had seen Citrix web sessions hijacked with authentication granted without the user's knowledge, one session reused from both expected and suspicious IP addresses, LDAP queries and ADExplorer64.exe runs consistent with Active Directory reconnaissance, and sessions from data-centre addresses linked to consumer VPN services. The same day, according to The Register, NetScaler senior vice president Anil Shetty wrote: "There is no evidence to suggest exploitation of CVE-2025-5777."
The technical picture filled in during early July. watchTowr Labs published an analysis on 4 July showing that sending the login parameter without a value makes the appliance return leftover stack memory inside an XML tag, a variable amount each time. In its own lab watchTowr did not find cookies or session IDs in the leaked data, though it noted production gateways would hold more. On 7 July Horizon3.ai went further, writing that "it's possible to receive legitimate user session tokens via this vector" and that "we can see a session token leaked that belongs to the 'nsroot' user", the appliance's built-in administrator. Horizon3.ai also reported plaintext credentials from legitimate login requests, while cautioning that sparse advisories made it hard to be sure which of the year's NetScaler bugs it had reproduced.
CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities catalogue on 10 July, citing evidence of active exploitation. Citrix then updated its blog: "At the time we announced CVE-2025-5777, there was no evidence to suggest exploitation." By 18 July SecurityWeek reported that at least 100 organisations had been hacked, that Imperva had seen close to 12 million attacks by 11 July, and that the Shadowserver Foundation still counted about 4,700 unpatched instances on 17 July. Beaumont described the activity as "clearly spray and pray".
Timeline
| Date | Event |
|---|---|
| 17 June 2025 | Citrix publishes bulletin CTX693420 and fixed builds for CVE-2025-5777 and CVE-2025-5349. |
| 20 June 2025 | Exploitation begins, according to Kevin Beaumont as reported by SecurityWeek. |
| 23 June 2025 | GreyNoise honeypots record exploitation attempts, according to Beaumont (SecurityWeek gives 24 June as GreyNoise's first observation). |
| 26 June 2025 | ReliaQuest reports likely active exploitation; Citrix says there is no evidence of exploitation. |
| 4 July 2025 | watchTowr Labs publishes a technical analysis and a detection check. |
| 7 July 2025 | Horizon3.ai publishes a working exploit write-up showing session tokens in leaked memory. |
| 10 July 2025 | CISA adds CVE-2025-5777 to the Known Exploited Vulnerabilities catalogue (Citrix's update gives 11 July). |
| 11 July 2025 | Citrix updates its blog and urges customers to install the fixed builds immediately. |
| 17 July 2025 | Shadowserver counts about 4,700 unpatched NetScaler instances. |
| 18 July 2025 | SecurityWeek reports at least 100 organisations hacked. |
How it happened: the identity attack path
- Find an exposed gateway. Attackers scanned the internet for NetScaler appliances running as a VPN, ICA Proxy or AAA virtual server, the configurations Citrix lists as affected.
- Bleed memory. A login request with a malformed login field made the appliance return a fragment of uninitialised memory. Repeating the request returned more fragments.
- Harvest session tokens. Some fragments contained session tokens belonging to users who had already signed in, and in Horizon3.ai's tests, plaintext credentials and an administrator session.
- Replay the session. Presenting a stolen token let the attacker resume the user's authenticated session. Because MFA had already been completed, it was never asked for again.
- Move inside. In the activity ReliaQuest observed, the hijacked sessions were followed by LDAP queries and ADExplorer64.exe runs to map Active Directory.
Impact
- Confirmed: active exploitation, confirmed by CISA's KEV listing and multiple threat intelligence firms; at least 100 organisations hacked, according to SecurityWeek's reporting.
- Observed by researchers: hijacked sessions with MFA bypassed and Active Directory reconnaissance (ReliaQuest); close to 12 million attack attempts by 11 July (Imperva).
- Potential: takeover of appliance administration through a leaked "nsroot" session, and credential theft from login traffic, as Horizon3.ai demonstrated in its research.
- Lingering exposure: about 4,700 unpatched instances on 17 July (Shadowserver), and patched appliances remained at risk until existing sessions were terminated.
What this means for NHI governance
We classify CitrixBleed 2 as a human-identity breach, in line with how we treated CitrixBleed 2023. The sessions attackers reported stealing belonged to employees using VPN and Citrix access. It still belongs in an identity library, because the stolen item was not a password but a bearer token: whoever holds it is the user, and MFA has already been satisfied. The same property makes machine tokens dangerous, and the same controls apply.
Two lessons carry over to non-human identities. First, an edge appliance that terminates authentication holds every active session in memory, including administrative ones such as "nsroot", so a single memory disclosure bug exposes them all at once. Second, the fix is not complete until the stolen material is invalidated. Citrix's guidance to kill all ICA and PCoIP sessions after upgrading, and Beaumont's criticism that it did not clearly cover every session type, show how easy it is to patch the hole and leave the stolen tokens working. Our Token and Session Security Guide and Remote Access Identity Guide cover session binding, lifetimes and revocation.
Recommendations
- Patch and then kill every session. Upgrade to the fixed builds, then terminate all ICA, PCoIP, VPN and AAA sessions so tokens stolen before the patch stop working. See our Token and Session Security Guide.
- Hunt for session reuse. Look for one session ID used from several IP addresses, sessions from data-centre or consumer VPN ranges, and sessions with no matching MFA event. See our ITDR Guide.
- Shorten gateway session lifetimes. Long-lived VPN and virtual desktop sessions give stolen tokens a long shelf life. Bind sessions to device or client context where the platform allows it. See our Remote Access Identity Guide.
- Treat appliance admin accounts as privileged identities. Rotate "nsroot" and other administrator credentials after any memory disclosure, and restrict management interfaces to trusted networks. See our Privileged Access Management Guide.
- Check for exploitation even if you patched quickly. Exploitation began within days of the fix, so review gateway logs from 17 June 2025 onwards using Citrix's published guidance.
- Watch for reconnaissance after remote access. LDAP enumeration and tools such as ADExplorer soon after a gateway login are a strong signal of a hijacked session.
Frequently asked questions
What is CitrixBleed 2?
CitrixBleed 2 is the nickname for CVE-2025-5777, a memory overread in Citrix NetScaler ADC and NetScaler Gateway disclosed on 17 June 2025. A malformed login request makes the appliance return fragments of memory that can include live session tokens, letting attackers hijack authenticated sessions and bypass MFA.
Was CitrixBleed 2 exploited in the wild?
Yes. ReliaQuest reported likely exploitation on 26 June 2025, CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 10 July 2025, and SecurityWeek reported at least 100 organisations hacked by 18 July. Citrix initially said it had no evidence of exploitation and later updated its statement.
Is patching NetScaler enough to fix CitrixBleed 2?
No. Session tokens stolen before the patch keep working until the sessions end. Citrix advises terminating all active ICA and PCoIP sessions after upgrading every appliance in a pair or cluster, and organisations should also clear other session types and review logs for hijacked sessions.
Related NHI Mgmt Group resources
CitrixBleed 2023 · Ivanti Connect Secure exploitation 2024 · Change Healthcare breach 2024 · Token and Session Security Guide · Remote Access Identity Guide
How NHI Mgmt Group can help
Session tokens, API keys and service credentials all share one weakness: whoever holds them is trusted. We help identity and security teams find where those bearer credentials live, shorten their lifetimes and build revocation into incident response. See our NHI Foundation Level Training Course.
References
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-5349 and CVE-2025-5777 (17 June 2025)
- ReliaQuest: Threat Spotlight: CVE-2025-5777: Citrix Bleed 2 Opens Old Wounds (26 June 2025)
- BleepingComputer: Citrix Bleed 2 flaw now believed to be exploited in attacks (27 June 2025)
- watchTowr Labs: How Much More Must We Bleed? Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777) (4 July 2025)
- Horizon3.ai: CVE-2025-5777: CitrixBleed 2 Write-Up... Maybe? (7 July 2025)
- The Register: Now everybody but Citrix agrees that CitrixBleed 2 is under exploit (10 July 2025)
- SecurityWeek: CitrixBleed 2: 100 Organizations Hacked, Thousands of Instances Still Vulnerable (18 July 2025)