Monday, 28 Jul 2025
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • 🔥
  • Technology
  • World
  • Finance
  • Politics
  • Travel
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

CISA warns hackers are actively exploiting critical CitrixBleed 2

Nexpressdaily
Last updated: July 14, 2025 2:33 pm
Nexpressdaily
Share
SHARE


  • CitrixBleed 2 was discovered in mid-June 2025
  • But there were quickly reports of abuse in the wild
  • CISA is now urging FCEB agencies to patch immediately

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CitrixBleed 2 to its Known Exploited Vulnerabilities (KEV) catalog, alerting Federal Civilian Branch Agencies (FCEB), as well as other businesses, that the bug is being actively exploited in the wild.

On July 10, CISA added CVE-2025-5777 to the catalog – a critical-severity (9.3/10) insufficient input validation vulnerability that leads to memory overread. It affects Citrix NetScaler ADC and NetScaler Gateway devices, versions 14.1 and before 47.46, and from 13.1 and before 59.19.

It can be abused against vulnerable NetScaler ADC and NetScaler Gateway appliances to extract sensitive memory contents, including session tokens, credentials, and potentially other user data, without authentication. Given its similarity to a previous Citrix vulnerability called CitrixBleed, security researchers dubbed it CitrixBleed 2.


You may like

“Significant risk”

The bug was first discovered in mid-June 2025, and by early July, there were already reports of abuse in the wild.

Citrix released a patch but apparently, the majority of instances have not yet been patched, presenting a unique opportunity for cybercriminals.

Multiple security researchers, including ReliaQuest, watchTowr, and Horizon3.ai, have warned users of ongoing exploitation campaigns. Akamai also added that it observed a “drastic increase” in scanning for potentially vulnerable NetScaler endpoints.

Now, CISA also confirmed the reports of in-the-wild attacks.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” it said in a short security advisory.

What’s also interesting is the tight deadline it gave FCEB agencies to patch their endpoints. Usually, agencies have 21 days to apply the patch or stop using the affected software altogether. In this case, the deadline was – just 24 hours.

Citrix has not yet unequivocally stated that the bugs were being exploited. It did, however, urge everyone to apply the patch without delay.

Via TechCrunch

You might also like

Share This Article
Email Copy Link Print
Previous Article ‘Schengen, the euro, the whole thing’: Readers say UK must fully commit to rejoining EU
Next Article The unlikely rise of Karyn Tomlinson, who traveled to France in her 20s to learn how to cook and just won the culinary world’s most prestigious award

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

Key Home Goods Unveils Limited Edition Cutting Board Collection: Where Functional Art Meets Heritage Craftsmanship

DALLAS, June 21, 2025 (GLOBE NEWSWIRE) -- Key Home Goods, a design-forward brand rooted in…

By Nexpressdaily

This Nasdaq ETF Could Turn $500 Monthly Into $1 Million

The $1 million mark is a significant financial milestone for many people. There's something about…

By Nexpressdaily

Trump DOJ order on Jeffrey Epstein could create legal and ethical challenges

President Donald Trump has directed Attorney General Pam Bondi to "produce any and all pertinent…

By Nexpressdaily

You Might Also Like

Technology

AMD subtly confirms reveal date for its next Radeon GPU – an ideal time to compete with Nvidia at Computex 2025

By Nexpressdaily
Technology

Today’s NYT Mini Crossword Answers for July 24

By Nexpressdaily
Technology

London-based Origin, which offers software to help HR teams administer employee benefits, emerges from stealth with a $21M Series A led by Felix Capital (Lucy Adams/Tech.eu)

By Nexpressdaily
Technology

Is the Galaxy Z Fold or Flip ready to be an Ultra? Samsung just set July 9 as it’s next Galaxy Unpacked

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?