WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) Active Exploitation of CitrixBleed 2 (CVE-2025-5777), Check for Compromise Even if You’ve Patched
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Active Exploitation of CitrixBleed 2 (CVE-2025-5777), Check for Compromise Even if You’ve Patched

TLP:CLEAR

Author: Chase Snow

Created: Thursday, July 10, 2025 - 14:57

Categories: Cybersecurity, Security Preparedness

Summary: Due to several security research companies’ findings of active exploitation of a high-severity vulnerability in Citrix devices affecting NetScaler ADC and Gateway (CVE-2025-5777) dubbed CitrixBleed 2, members are encouraged to check for probing or compromise of these devices. While Citrix has officially stated they have no evidence of in-the-wild exploitation, watchtower, Horizon3.ai, and ReliaQuest researchers have all shared insights into this vulnerability and evidence suggesting active exploitation.

Analyst Note: Given the criticality of CVE-2025-5777, readily available exploit code, and the ubiquity of Citrix NetScaler ADC and Gateway devices, WaterISAC is sharing this information to increase situational awareness and encourage members to patch vulnerable systems immediately and to check for probing or compromise even if you’ve already patched.

Affected Versions:

  • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-43.56
  • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-58.32
  • NetScaler ADC 13.1-FIPS and NDcPP  BEFORE 13.1-37.235-FIPS and NDcPP
  • NetScaler ADC 12.1-FIPS BEFORE 12.1-55.328-FIPS

Original Source: https://www.helpnetsecurity.com/2025/07/08/cve-2025-5777-indicators-of-compromise/

Additional Reading:

  • How Much More Must We Bleed? – Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)
  • CVE-2025-5777: CitrixBleed 2 Write-Up… Maybe?
  • Threat Spotlight: CVE-2025-5777: Citrix Bleed 2 Opens Old Wounds

Mitigation Recommendations:

  • CitrixBleed 2 might be actively exploited (CVE-2025-5777)

Related WaterISAC PIRs: 6, 8, 10, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar