Vulnerability
Exploitation Wave
Citrix NetScaler CVE-2025-7775 exploitation and fast weaponization
Updated 03.09.2025 21:03
Case score 64
Score breakdown
- Total
- 64
- Lead score
- 62
- Support bonus
- +2 / 20
- Scoring support
- 1
- Context members
- 0
Top contributors
- Vulnerability Active exploitation, high severity, and urgent patching requirements make this the anchor event. base
- Exploitation Wave Adds follow-on weaponization evidence showing rapid abuse of the same Citrix NetScaler flaw family. support
Case score 64
Members 2
Latest activity 03.09.2025 21:03
Active exploitation
Patch available
CVSS: 9.2 Critical
Active exploitation
Patch available
CVSS: 9.2 Critical
Members 2
First seen 26.08.2025 23:04
Last seen 03.09.2025 15:20
Updated 03.09.2025 21:03
Overview
**CVE-2025-7775** is an actively exploited memory overflow in **Citrix NetScaler ADC and NetScaler Gateway** that can hijack exposed appliances or force denial of service. The flaw affects VPN and remote-access deployments, and available evidence says exploitation has already been observed on unmitigated systems.
Citrix released fixes for **CVE-2025-7775**, **CVE-2025-7776**, and **CVE-2025-8424**, while **CISA** placed **CVE-2025-7775** in the **KEV** catalog and ordered Federal Civilian Executive Branch agencies to remediate it within 48 hours. Later chatter around **HexStrike AI** showed attackers trying to speed exploitation of the same Citrix flaw family, so exposed appliances still face urgent patch pressure.
Attackers are exploiting **CVE-2025-7775** in **Citrix NetScaler ADC and NetScaler Gateway** appliances to trigger memory overflow, hijack systems, or force denial of service. The flaw affects deployments used for VPN or remote access, and it can also be reached on systems handling certain IPv6 web traffic or content routing tasks. Citrix rated the issue 9.2/10 because exploitation does not require credentials or user interaction. Available evidence says exploitation has been observed on unmitigated appliances, and supported 12.1, 13.1, and 14.1 release lines are affected alongside unsupported end-of-life versions.
Citrix released fixes for **CVE-2025-7775**, **CVE-2025-7776**, and **CVE-2025-8424**, and said no workarounds are available. CISA added **CVE-2025-7775** to the **KEV** catalog and required Federal Civilian Executive Branch agencies to remediate it within 48 hours. A later exploitation wave reported forum chatter that threat actors were using **HexStrike AI** to automate attacks against the newly disclosed Citrix flaws, which shortens the window between disclosure and abuse.