Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave

Citrix NetScaler CVE-2025-7775 exploitation and fast weaponization

Updated 03.09.2025 21:03
Case score 64
Members 2 First seen 26.08.2025 23:04 Latest activity 03.09.2025 21:03

Overview

**CVE-2025-7775** is an actively exploited memory overflow in **Citrix NetScaler ADC and NetScaler Gateway** that can hijack exposed appliances or force denial of service. The flaw affects VPN and remote-access deployments, and available evidence says exploitation has already been observed on unmitigated systems. Citrix released fixes for **CVE-2025-7775**, **CVE-2025-7776**, and **CVE-2025-8424**, while **CISA** placed **CVE-2025-7775** in the **KEV** catalog and ordered Federal Civilian Executive Branch agencies to remediate it within 48 hours. Later chatter around **HexStrike AI** showed attackers trying to speed exploitation of the same Citrix flaw family, so exposed appliances still face urgent patch pressure.
Latest development Open development history 2 earlier developments Threat actors claim HexStrike AI exploitation of Citrix NetScaler flaws Threat actors are trying to weaponize the newly released HexStrike AI offensive security platform to exploit recently disclosed Citrix vulnerabilities, with darknet forum discussions claiming successful exploitation of the three flaws Citrix disclosed last week and, in some cases, vulnerable NetScaler instances being offered to other criminals for sale. Check Point says the activity can shrink the time between public disclosure and mass exploitation while automating repeated attack attempts.
  1. Earlier development

    Hackers use HexStrike-AI to exploit Citrix NetScaler CVE-2025-7775

    Check Point Research observed dark web chatter linking HexStrike-AI to rapid weaponization of newly disclosed Citrix NetScaler ADC and Gateway vulnerabilities, with attackers reportedly using the framework to automate scanning for vulnerable instances, crafting exploits, delivering payloads, and maintaining persistence after unauthenticated remote code execution through CVE-2025-7775 and webshell deployment on compromised appliances.

  2. Earlier development

    Citrix discloses active NetScaler CVE-2025-7775 exploitation

    Citrix disclosed three new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, including CVE-2025-7775, a zero-day memory overflow that can enable system hijacking or a DoS condition on VPN or remote access deployments and on devices handling certain IPv6 web traffic or specific content routing tasks. Citrix said exploits of CVE-2025-7775 on unmitigated appliances have been observed, identified affected builds in the 12.1, 13.1, and 14.1 release lines, listed CVE-2025-7776 and CVE-2025-8424, and urged affected customers to install the relevant updated versions as soon as possible because unsupported, end-of-life versions are also affected.

Signals

Exploitation
CVEs/products
Remediation

Threat actor context

1 listed

Technical intelligence

Existing Case data

Member happenings

Vulnerability Citrix NetScaler ADC and Gateway actively exploited memory overflow denial-of-service flaw (CVE-2025-7775)
Updated 26.08.2025 23:04 Lead Contribution 62
Exploitation Active Exploitation Data Type Passwords CVSS 9.2 Critical Patch Patch Available

**CVE-2025-7775** is an **actively exploited** memory overflow in **Citrix NetScaler ADC and NetScaler Gateway**, creating **system hijack** and **DoS** risk for **VPN and remote-access** deployments. The flaw can also be triggered on systems handling **certain IPv6 web traffic** or **content routing** tasks, widening exposure beyond standard remote access use. Citrix has released updates for supported builds, but **unsupported release lines** remain exposed until they are removed or replaced. The issue affects **12.1, 13.1, and 14.1** branches, and exploitation against **unmitigated appliances** makes timely remediation critical.

Exploitation Wave Citrix NetScaler flaws exploited via HexStrike AI
Updated 03.09.2025 15:20 Scoring Support Contribution 1
Exploitation Active Exploitation

Threat actors are using **HexStrike AI** to exploit **three Citrix flaws** disclosed **last week**, accelerating abuse of **NetScaler** systems. Forum posts claim successful exploitation and show some vulnerable instances being offered for sale. The wave compresses the time from disclosure to mass exploitation and increases automation of repeat attack attempts.