
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7775 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to achieve Remote Code Execution (RCE) and/or Denial of Service (DoS). The vulnerability affects systems configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, as well as LB virtual servers of type HTTP, SSL, or HTTP_QUIC bound with IPv6 services, and CR virtual servers with type HDX. Affected versions include NetScaler ADC/Gateway 13.1 (before 13.1-59.22), 14.1 (before 14.1-47.48), 12.1-FIPS and NDcPP (before 12.1-55.330), and 13.1-FIPS and NDcPP (before 13.1-37.241). Disclosed and patched on August 26–27, 2025, it carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Citrix Advisory, CISA KEV).
The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a memory overflow condition in the NetScaler processing stack. The vulnerability is exploitable over the network with no authentication, no privileges required, and no user interaction, making it a pre-authentication RCE. Exploitation is triggered when the appliance is configured in one of the affected roles (Gateway, AAA, LB with IPv6, or CR with HDX), allowing a remote attacker to send specially crafted network requests that overflow memory buffers and potentially redirect execution flow. Multiple public proof-of-concept exploits have been published on GitHub, and the AI-powered tool HexStrike was reported to have weaponized this vulnerability within minutes of disclosure (Citrix Advisory, Rapid7 ETR, BleepingComputer HexStrike).
Successful exploitation enables complete compromise of the affected NetScaler ADC or Gateway appliance, allowing attackers to execute arbitrary code with the privileges of the NetScaler process, establish persistent access (e.g., web shells), exfiltrate sensitive data including VPN credentials and session tokens, or cause a denial of service. Because NetScaler devices typically serve as network access gateways, compromise can facilitate lateral movement into internal enterprise networks. Over 28,200 internet-exposed NetScaler instances were identified as vulnerable following disclosure, and active exploitation has included web shell deployment (BleepingComputer, Security Affairs).
CVE-2025-7775 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 26, 2025, with a remediation due date of August 28, 2025, confirming active in-the-wild exploitation at the time of disclosure (CISA KEV). Multiple public PoC exploits are available on GitHub (e.g., swabird/CVE-2025-7775-PoC, rxerium/CVE-2025-7775, mr-r3b00t/CVE-2025-7775, Aaqilyousuf/CVE-2025-7775-vulnerable-lab). The AI-powered red-team tool HexStrike was reported to have been weaponized by threat actors to exploit this and related NetScaler flaws within approximately 10 minutes of availability (BleepingComputer HexStrike, The Register). The EPSS score is approximately 0.1225 (12.25%), and the vulnerability has been associated with GhostEmperor threat actor activity in threat intelligence reporting. The KEV catalog notes the vulnerability is of unknown association with ransomware campaigns (CISA KEV).
.php, .asp, .jsp) in NetScaler web directories; new or modified files in /var/netscaler/ or /nsconfig/ directories; unauthorized SSH keys added to the appliance.ns.log or httperror.log entries showing crashes, segmentation faults, or unexpected process restarts; access logs with anomalous request patterns or oversized payloads to gateway endpoints; authentication logs showing access without valid credentials.nsppe or nshttpd processes; unusual shell processes (/bin/sh, bash) running under NetScaler service accounts.Citrix released patches on August 27, 2025 via security bulletin CTX694938. Organizations should upgrade to the following fixed versions immediately:
Note: NetScaler ADC and Gateway version 12.1 is End of Life and should be upgraded to a supported version. As an interim measure, restrict network access to NetScaler management interfaces to trusted IP ranges only, enable enhanced logging, and conduct forensic review of appliances for signs of compromise. CISA mandated remediation for federal agencies by August 28, 2025 (Citrix Advisory, CISA KEV).
Citrix/NetScaler published security bulletin CTX694938 on August 27, 2025, confirming active exploitation and urging immediate patching (Citrix Advisory). CISA added the vulnerability to its KEV catalog on the same day as disclosure (August 26, 2025), with an unusually tight 2-day remediation deadline for federal agencies, underscoring the severity of active exploitation (CISA KEV). Security researcher Kevin Beaumont (GossiTheDog) was among the first to publicly flag the exploitation activity on social media. Multiple national CERTs including CERT-EU, the Canadian Centre for Cyber Security, HKCERT, and Australia's ASD issued advisories. The subsequent discovery that the AI tool HexStrike was being used to rapidly weaponize this and related NetScaler flaws generated significant media coverage and community discussion about AI-accelerated exploitation (BleepingComputer HexStrike, The Register). The Shadowserver Foundation reported scanning data showing over 28,200 vulnerable internet-exposed instances, amplifying urgency across the security community.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."