Citrix NetScaler CVE-2025-7775 exploitation and fast weaponization
Case score 64
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 64
- Main story score
- 62
- Related evidence lift
- +2 / 20
- Contributing updates
- 1
- Context updates
- 0
- Vulnerability Active exploitation, high severity, and urgent patching requirements make this the anchor event. main
- Exploitation Wave Adds follow-on weaponization evidence showing rapid abuse of the same Citrix NetScaler flaw family. contributes
Overview
Latest development Open development history Threat actors claim HexStrike AI exploitation of Citrix NetScaler flaws Threat actors are trying to weaponize the newly released HexStrike AI offensive security platform to exploit recently disclosed Citrix vulnerabilities, with darknet forum discussions claiming successful exploitation of the three flaws Citrix disclosed last week and, in some cases, vulnerable NetScaler instances being offered to other criminals for sale. Check Point says the activity can shrink the time between public disclosure and mass exploitation while automating repeated attack attempts.
-
Hackers use HexStrike-AI to exploit Citrix NetScaler CVE-2025-7775
Check Point Research observed dark web chatter linking HexStrike-AI to rapid weaponization of newly disclosed Citrix NetScaler ADC and Gateway vulnerabilities, with attackers reportedly using the framework to automate scanning for vulnerable instances, crafting exploits, delivering payloads, and maintaining persistence after unauthenticated remote code execution through CVE-2025-7775 and webshell deployment on compromised appliances.
-
Citrix discloses active NetScaler CVE-2025-7775 exploitation
Citrix disclosed three new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, including CVE-2025-7775, a zero-day memory overflow that can enable system hijacking or a DoS condition on VPN or remote access deployments and on devices handling certain IPv6 web traffic or specific content routing tasks. Citrix said exploits of CVE-2025-7775 on unmitigated appliances have been observed, identified affected builds in the 12.1, 13.1, and 14.1 release lines, listed CVE-2025-7776 and CVE-2025-8424, and urged affected customers to install the relevant updated versions as soon as possible because unsupported, end-of-life versions are also affected.