Sunday, 27 Jul 2025
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • đŸ”„
  • Technology
  • World
  • Finance
  • Politics
  • Travel
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

CISA warns hackers are actively exploiting critical CitrixBleed 2

Nexpressdaily
Last updated: July 14, 2025 2:33 pm
Nexpressdaily
Share
SHARE


  • CitrixBleed 2 was discovered in mid-June 2025
  • But there were quickly reports of abuse in the wild
  • CISA is now urging FCEB agencies to patch immediately

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CitrixBleed 2 to its Known Exploited Vulnerabilities (KEV) catalog, alerting Federal Civilian Branch Agencies (FCEB), as well as other businesses, that the bug is being actively exploited in the wild.

On July 10, CISA added CVE-2025-5777 to the catalog – a critical-severity (9.3/10) insufficient input validation vulnerability that leads to memory overread. It affects Citrix NetScaler ADC and NetScaler Gateway devices, versions 14.1 and before 47.46, and from 13.1 and before 59.19.

It can be abused against vulnerable NetScaler ADC and NetScaler Gateway appliances to extract sensitive memory contents, including session tokens, credentials, and potentially other user data, without authentication. Given its similarity to a previous Citrix vulnerability called CitrixBleed, security researchers dubbed it CitrixBleed 2.


You may like

“Significant risk”

The bug was first discovered in mid-June 2025, and by early July, there were already reports of abuse in the wild.

Citrix released a patch but apparently, the majority of instances have not yet been patched, presenting a unique opportunity for cybercriminals.

Multiple security researchers, including ReliaQuest, watchTowr, and Horizon3.ai, have warned users of ongoing exploitation campaigns. Akamai also added that it observed a “drastic increase” in scanning for potentially vulnerable NetScaler endpoints.

Now, CISA also confirmed the reports of in-the-wild attacks.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” it said in a short security advisory.

What’s also interesting is the tight deadline it gave FCEB agencies to patch their endpoints. Usually, agencies have 21 days to apply the patch or stop using the affected software altogether. In this case, the deadline was – just 24 hours.

Citrix has not yet unequivocally stated that the bugs were being exploited. It did, however, urge everyone to apply the patch without delay.

Via TechCrunch

You might also like

Share This Article
Email Copy Link Print
Previous Article ‘Schengen, the euro, the whole thing’: Readers say UK must fully commit to rejoining EU
Next Article The unlikely rise of Karyn Tomlinson, who traveled to France in her 20s to learn how to cook and just won the culinary world’s most prestigious award

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

After Soaring by 80% During the First Half of 2025, Could This Unstoppable Artificial Intelligence (AI) Stock Be Wall Street’s Next Stock-Split Candidate?

Palantir was the top-performing stock in the S&P 500 and Nasdaq-100 during the first half…

By Nexpressdaily

What to know about the impacts of the Supreme Court’s ruling on transgender care for youth

The U.S. Supreme Court has upheld Tennessee's ban on gender-affirming surgery for transgender youth in…

By Nexpressdaily

Kyiv releases new drone footage of Operation ‘Spiderweb’ as more details emerge

Published on 04/06/2025 - 18:24 GMT+2‱Updated 18:26ADVERTISEMENTUkraine’s security service (SBU) released new drone footage of…

By Nexpressdaily

You Might Also Like

Technology

The Drifter is a good old-fashioned thriller

By Nexpressdaily
Technology

Invincible VS Is a Tag-Team Brawler Packed With Bloody Superhero Carnage

By Nexpressdaily
Technology

Meta faces Democratic probe into plans to power a giant data center with gas

By Nexpressdaily
Technology

Moonshot's Kimi K2 uses a 1T-parameter MoE architecture with 32B active parameters and outperforms models like GPT-4.1 and DeepSeek-V3 on key benchmarks (Michael Nuñez/VentureBeat)

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?