HomeSecurityExploits for NetScaler's CitrixBleed2 flaw released publicly

Exploits for NetScaler's CitrixBleed2 flaw released publicly

Researchers have published exploits for a critical flaw in Citrix NetScaler, known as CVE-2025-5777 and codenamed CitrixBleed2, warning that it is extremely easy to exploit and allows the interception of user session tokens.

See also: Citrix: NetScaler vulnerability used for DoS attacks

CitrixBleed 2 flaw

The CitrixBleed2 vulnerability affects Citrix NetScaler ADC and Gateway appliances and allows attackers to recover memory contents simply by sending malformed POST requests during login attempts .

This critical flaw is named CitrixBleed2 because it closely resembles the original CitrixBleed bug (CVE-2023-4966) from 2023, which was exploited by ransomware and in attacks against government organizations to hijack user sessions and compromise networks.

In technical analyses first published by watchTowr and then by Horizon3, researchers confirmed that the vulnerability can be exploited by sending a malformed login request, where the login= parameter is modified to be sent without the equal sign or value. This results in the NetScaler appliance displaying memory contents up to the first null character in the section. of the response.<InitialValue></InitialValue>

See also: Citrix: Connection problems after NetScaler update

The vulnerability is caused by the use of the snprintf in combination with a format string that includes %.*s. According to Horizon3, each request exposes approximately 127 bytes of data, allowing attackers to make repeated HTTP requests to extract additional memory content until they locate the sensitive data they are looking for.

Exploits for NetScaler's CitrixBleed2 flaw released publicly
Publicly released exploits for CitrixBleed2 NetScaler flaw

While WatchTowr's efforts were unsuccessful, Horizon3 demonstrates in a video that it was able to exploit the vulnerability to steal user session tokens. Furthermore, Horizon3 notes that the vulnerability is not limited to NetScaler endpoints, but can also be exploited against configuration tools used by system administrators.

Citrix continues to state that the CitrixBleed2 flaw is not being actively exploited, something it has admitted in a related post on its official blog.

However, a report published in June by cybersecurity firm ReliaQuestsaid there were indications that the CVE-2025-5777 vulnerability may already have been exploited in attacks, as the company observed an increase in incidents of user session hijacking.

See also: Citrix: NetScaler vulnerability used for DoS attacks

Furthermore, security researcher Kevin Beaumont disputes Citrix's official statement, claiming that the vulnerability has been actively exploited since mid-June, with attackers using it to extract memory content and hijack sessions.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS