CVE-2025-7775: 
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2025-7775 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to achieve Remote Code Execution (RCE) and/or Denial of Service (DoS). The vulnerability affects systems configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, as well as LB virtual servers of type HTTP, SSL, or HTTP_QUIC bound with IPv6 services, and CR virtual servers with type HDX. Affected versions include NetScaler ADC/Gateway 13.1 (before 13.1-59.22), 14.1 (before 14.1-47.48), 12.1-FIPS and NDcPP (before 12.1-55.330), and 13.1-FIPS and NDcPP (before 13.1-37.241). Disclosed and patched on August 26–27, 2025, it carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Citrix Advisory, CISA KEV).

Technical details

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a memory overflow condition in the NetScaler processing stack. The vulnerability is exploitable over the network with no authentication, no privileges required, and no user interaction, making it a pre-authentication RCE. Exploitation is triggered when the appliance is configured in one of the affected roles (Gateway, AAA, LB with IPv6, or CR with HDX), allowing a remote attacker to send specially crafted network requests that overflow memory buffers and potentially redirect execution flow. Multiple public proof-of-concept exploits have been published on GitHub, and the AI-powered tool HexStrike was reported to have weaponized this vulnerability within minutes of disclosure (Citrix Advisory, Rapid7 ETR, BleepingComputer HexStrike).

Impact

Successful exploitation enables complete compromise of the affected NetScaler ADC or Gateway appliance, allowing attackers to execute arbitrary code with the privileges of the NetScaler process, establish persistent access (e.g., web shells), exfiltrate sensitive data including VPN credentials and session tokens, or cause a denial of service. Because NetScaler devices typically serve as network access gateways, compromise can facilitate lateral movement into internal enterprise networks. Over 28,200 internet-exposed NetScaler instances were identified as vulnerable following disclosure, and active exploitation has included web shell deployment (BleepingComputer, Security Affairs).

Exploitability

CVE-2025-7775 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 26, 2025, with a remediation due date of August 28, 2025, confirming active in-the-wild exploitation at the time of disclosure (CISA KEV). Multiple public PoC exploits are available on GitHub (e.g., swabird/CVE-2025-7775-PoC, rxerium/CVE-2025-7775, mr-r3b00t/CVE-2025-7775, Aaqilyousuf/CVE-2025-7775-vulnerable-lab). The AI-powered red-team tool HexStrike was reported to have been weaponized by threat actors to exploit this and related NetScaler flaws within approximately 10 minutes of availability (BleepingComputer HexStrike, The Register). The EPSS score is approximately 0.1225 (12.25%), and the vulnerability has been associated with GhostEmperor threat actor activity in threat intelligence reporting. The KEV catalog notes the vulnerability is of unknown association with ransomware campaigns (CISA KEV).

Exploitation steps

  1. Reconnaissance: Use Shodan, Censys, or FOFA to identify internet-facing Citrix NetScaler ADC and Gateway appliances running vulnerable versions (13.1 < 59.22, 14.1 < 47.48, 12.1-FIPS/NDcPP < 55.330, 13.1-FIPS/NDcPP < 37.241). Confirm the appliance is configured as a Gateway, AAA, LB with IPv6, or CR with HDX virtual server.
  2. Fingerprinting: Send HTTP requests to the NetScaler management or virtual server interface to confirm version and configuration via response headers or login pages.
  3. Craft malicious payload: Prepare a specially crafted network request designed to trigger the memory overflow condition in the affected NetScaler processing component. Public PoC code (e.g., from GitHub repositories) provides templates for this payload.
  4. Send exploit request: Transmit the crafted request to the target appliance without authentication. The memory overflow is triggered server-side, potentially allowing control of execution flow.
  5. Achieve RCE or DoS: Depending on exploit reliability and memory layout, the attacker may achieve arbitrary code execution (e.g., dropping a web shell or reverse shell) or cause a denial of service crash of the NetScaler process.
  6. Establish persistence: If RCE is achieved, deploy a web shell or backdoor in the NetScaler file system to maintain persistent access, then pivot to internal network resources accessible through the gateway (Rapid7 ETR, BleepingComputer).

Indicators of compromise

  • Network: Unusual or malformed HTTP/HTTPS requests to NetScaler virtual server interfaces, particularly from unexpected source IPs; outbound connections from the NetScaler appliance to unknown external IPs (potential C2 beaconing); scanning activity targeting NetScaler management ports.
  • File System: Unexpected web shell files (e.g., .php, .asp, .jsp) in NetScaler web directories; new or modified files in /var/netscaler/ or /nsconfig/ directories; unauthorized SSH keys added to the appliance.
  • Logs: NetScaler ns.log or httperror.log entries showing crashes, segmentation faults, or unexpected process restarts; access logs with anomalous request patterns or oversized payloads to gateway endpoints; authentication logs showing access without valid credentials.
  • Process: Unexpected child processes spawned by the NetScaler nsppe or nshttpd processes; unusual shell processes (/bin/sh, bash) running under NetScaler service accounts.
  • Threat Intelligence: GhostEmperor threat actor TTPs observed in post-exploitation activity; web shells consistent with those reported in active exploitation campaigns (Rapid7 ETR, Arctic Wolf, Nextron Systems).

Mitigation and workarounds

Citrix released patches on August 27, 2025 via security bulletin CTX694938. Organizations should upgrade to the following fixed versions immediately:

  • NetScaler ADC and Gateway 14.1: upgrade to 14.1-47.48 or later
  • NetScaler ADC and Gateway 13.1: upgrade to 13.1-59.22 or later
  • NetScaler ADC 12.1-FIPS: upgrade to 12.1-55.330 or later
  • NetScaler ADC 12.1-NDcPP: upgrade to 12.1-55.330 or later
  • NetScaler ADC 13.1-FIPS and NDcPP: upgrade to 13.1-37.241 or later

Note: NetScaler ADC and Gateway version 12.1 is End of Life and should be upgraded to a supported version. As an interim measure, restrict network access to NetScaler management interfaces to trusted IP ranges only, enable enhanced logging, and conduct forensic review of appliances for signs of compromise. CISA mandated remediation for federal agencies by August 28, 2025 (Citrix Advisory, CISA KEV).

Community reactions

Citrix/NetScaler published security bulletin CTX694938 on August 27, 2025, confirming active exploitation and urging immediate patching (Citrix Advisory). CISA added the vulnerability to its KEV catalog on the same day as disclosure (August 26, 2025), with an unusually tight 2-day remediation deadline for federal agencies, underscoring the severity of active exploitation (CISA KEV). Security researcher Kevin Beaumont (GossiTheDog) was among the first to publicly flag the exploitation activity on social media. Multiple national CERTs including CERT-EU, the Canadian Centre for Cyber Security, HKCERT, and Australia's ASD issued advisories. The subsequent discovery that the AI tool HexStrike was being used to rapidly weaponize this and related NetScaler flaws generated significant media coverage and community discussion about AI-accelerated exploitation (BleepingComputer HexStrike, The Register). The Shadowserver Foundation reported scanning data showing over 28,200 vulnerable internet-exposed instances, amplifying urgency across the security community.

Additional resources


Source: This report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88778HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88777HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88776HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88775HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026
CVE-2026-88774HIGH7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesSep 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management