Vulnerabilities & Exploits

Citrix NetScaler Exploitation Hits Gateways in the Wild

FortiGuard Labs says it has seen active exploitation of Citrix NetScaler ADC and NetScaler Gateway in the wild for CVE-2025-7775, a memory overflow flaw that can lead to remote code execution or denial of service. Citrix also issued related advisories for a second overflow bug, CVE-2025-7776, and a management-interface access-control issue, CVE-2025-8424, while CISA added CVE-2025-7775 to its Known Exploited Vulnerabilities catalog.

The overflow means a specially crafted request can make the appliance write past the end of memory, which can crash the device or let an attacker run code on it. FortiGuard says unpatched systems may also show dropped web shells or abnormal memory behavior, which turns a gateway bug into both a service-impacting problem and a possible foothold.

For organizations using NetScaler as a VPN, reverse proxy, or other access gate, the exposure sits at the choke point itself: if that layer is compromised, the path into internal services is compromised with it. The reporting does not settle how many appliances are already affected, but it does show the flaw is no longer theoretical.

1 source · Sep 29

CVE-2025-7775

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and… EPSS 20% (97th percentile).

CISA federal remediation date Aug 28 · date passed

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-09-28

Every edition of this story: Citrix NetScaler Exploitation Hits Gateways in the Wild

More from today