Article Details
Scrape Timestamp (UTC): 2025-08-26 17:33:11.770
Source: https://thehackernews.com/2025/08/citrix-patches-three-netscaler-flaws.html
Original Article Text
Click to Toggle View
Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775. Citrix has released fixes to address three security flaws in NetScaler ADC and NetScaler Gateway, including one that it said has been actively exploited in the wild. The vulnerabilities in question are listed below - The company acknowledged that "exploits of CVE-2025-7775 on unmitigated appliances have been observed," but stopped short of sharing additional details. However, for the flaws to be exploited, there are a number of prerequisites - The issues have been resolved in the following versions, with no available workarounds - Citrix credited Jimi Sebree of Horizon3.ai, Jonathan Hetzer of Schramm & Partnerfor and François Hämmerli for discovering and reporting the vulnerabilities. CVE-2025-7775 is the latest NetScaler ADC and Gateway vulnerability to be weaponized in real-world attacks in a short span of time, after CVE-2025-5777 (aka Citrix Bleed 2) and CVE-2025-6543. The disclosure also comes a day after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two security flaws impacting Citrix Session Recording (CVE-2024-8068 and CVE-2024-8069) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
Daily Brief Summary
Citrix has issued patches for three vulnerabilities in NetScaler ADC and Gateway, including CVE-2025-7775, which is actively exploited in the wild.
The vulnerabilities require specific conditions to be met for exploitation, with Citrix providing no workarounds, urging immediate patching.
Discoveries were credited to security researchers from Horizon3.ai, Schramm & Partnerfor, and independent expert François Hämmerli.
CVE-2025-7775 follows recent vulnerabilities like CVE-2025-5777 and CVE-2025-6543, marking a trend of rapid exploitation in Citrix products.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added related flaws to its Known Exploited Vulnerabilities catalog, indicating significant risk.
Organizations using NetScaler products should prioritize updates to mitigate potential threats and ensure system security.
This incident highlights the critical need for timely vulnerability management and collaboration with cybersecurity researchers.