tag
Citrixbleed2
CVE-2025-5777
web
CRITICAL 9.3
KEV
Ransomware
EPSS 100%
Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777)
CVE-2025-5777 ("CitrixBleed 2") is an unauthenticated out-of-bounds memory disclosure in Citrix NetScaler ADC/Gateway authentication processing. A crafted request can leak chunks of process memory that may contain active session tokens and credentials.…
Patched
2026-05-16