Researchers have published exploits for a critical flaw in Citrix NetScaler, known as CVE-2025-5777 and codenamed CitrixBleed2, warning that it is extremely easy to exploit and allows the interception of user session tokens.
See also: Citrix: NetScaler vulnerability used for DoS attacks

The CitrixBleed2 vulnerability affects Citrix NetScaler ADC and Gateway appliances and allows attackers to recover memory contents simply by sending malformed POST requests during login attempts .
This critical flaw is named CitrixBleed2 because it closely resembles the original CitrixBleed bug (CVE-2023-4966) from 2023, which was exploited by ransomware and in attacks against government organizations to hijack user sessions and compromise networks.
In technical analyses first published by watchTowr and then by Horizon3, researchers confirmed that the vulnerability can be exploited by sending a malformed login request, where the login= parameter is modified to be sent without the equal sign or value. This results in the NetScaler appliance displaying memory contents up to the first null character in the section. of the response.<InitialValue></InitialValue>
See also: Citrix: Connection problems after NetScaler update
The vulnerability is caused by the use of the snprintf in combination with a format string that includes %.*s. According to Horizon3, each request exposes approximately 127 bytes of data, allowing attackers to make repeated HTTP requests to extract additional memory content until they locate the sensitive data they are looking for.

While WatchTowr's efforts were unsuccessful, Horizon3 demonstrates in a video that it was able to exploit the vulnerability to steal user session tokens. Furthermore, Horizon3 notes that the vulnerability is not limited to NetScaler endpoints, but can also be exploited against configuration tools used by system administrators.
Citrix continues to state that the CitrixBleed2 flaw is not being actively exploited, something it has admitted in a related post on its official blog.
However, a report published in June by cybersecurity firm ReliaQuestsaid there were indications that the CVE-2025-5777 vulnerability may already have been exploited in attacks, as the company observed an increase in incidents of user session hijacking.
See also: Citrix: NetScaler vulnerability used for DoS attacks
Furthermore, security researcher Kevin Beaumont disputes Citrix's official statement, claiming that the vulnerability has been actively exploited since mid-June, with attackers using it to extract memory content and hijack sessions.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
