CVE-2025-5777

unknown KEV
Published 2025-07-10 · Modified 2025-07-10
CVSS v3
CVSS v2
VIR risk
1.5

Description

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

CISA KEV

Vendor
Citrix
Product
NetScaler ADC and Gateway
Due date
2025-07-11

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420 ; https://nvd.nist.gov/vuln/detail/CVE-2025-5777

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.