CVE-2025-7775
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and… EPSS 20% (97th percentile).
CISA federal remediation date Aug 28 · date passed
Vulnerabilities & Exploits
FortiGuard Labs says it has seen active exploitation of Citrix NetScaler ADC and NetScaler Gateway in the wild for CVE-2025-7775, a memory overflow flaw that can lead to remote code execution or denial of service. Citrix also issued related advisories for a second overflow bug, CVE-2025-7776, and a management-interface access-control issue, CVE-2025-8424, while CISA added CVE-2025-7775 to its Known Exploited Vulnerabilities catalog.
The overflow means a specially crafted request can make the appliance write past the end of memory, which can crash the device or let an attacker run code on it. FortiGuard says unpatched systems may also show dropped web shells or abnormal memory behavior, which turns a gateway bug into both a service-impacting problem and a possible foothold.
For organizations using NetScaler as a VPN, reverse proxy, or other access gate, the exposure sits at the choke point itself: if that layer is compromised, the path into internal services is compromised with it. The reporting does not settle how many appliances are already affected, but it does show the flaw is no longer theoretical.
1 source · Sep 29
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and… EPSS 20% (97th percentile).
CISA federal remediation date Aug 28 · date passed
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Vulnerability?FortiGuard Labs has observed active network telemetry relating to CVE-2025-7775, a memory overflow vulnerability in Citri...
originalPart of the PlainSec briefing for 2026-09-29
Every edition of this story: Citrix NetScaler Exploitation Hits Gateways in the Wild