Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Thousands of Citrix NetScaler Instances Unpatched Against Exploited Vulnerabilities

Thousands of Citrix NetScaler Instances Unpatched Against Exploited Vulnerabilities

Posted on July 1, 2025July 1, 2025 By CWS

1000’s of internet-exposed Citrix NetScaler cases are uncovered to assaults focusing on two just lately disclosed essential vulnerabilities, together with one exploited as a zero-day.

The failings, tracked as CVE-2025-5777 (CVSS rating of 9.3) and CVE-2025-6543 (CVSS rating of 9.2), are described as inadequate enter validation and reminiscence overflow points, and impression NetScaler cases configured as a gateway for distant entry or an AAA digital server. 

Profitable exploitation of the bugs may result in out-of-bounds reminiscence learn, and unintended management circulation and denial of service (DoS), respectively.

Shortly after Citrix disclosed CVE-2025–5777 on June 17, safety researcher Kevin Beaumont identified its similarity to CVE-2023-4966, known as CitrixBleed, and warned that tens of hundreds of probably affected cases might be seen on the web.

Final week, cybersecurity agency ReliaQuest mentioned it was seeing proof that CVE-2025–5777 could also be exploited within the wild for preliminary entry. Known as CitrixBleed2, the bug may be exploited to bypass authentication and facilitate session hijacking, the corporate mentioned.

On June 25, Citrix warned that CVE-2025-6543 had been exploited within the wild as a zero-day, urging instant patching. The corporate identified that the discontinued NetScaler ADC and NetScaler Gateway variations 12.1 and 13.0 are affected as effectively.

On June 30, the US cybersecurity company CISA added CVE-2025-6543 to its Identified Exploited Vulnerabilities (KEV) catalog, urging federal businesses to patch weak cases inside their environments by July 21.

Now, each Censys and The Shadowserver Basis warn that hundreds of NetScaler cases doubtlessly weak to at the very least one among these safety defects are uncovered to the web.Commercial. Scroll to proceed studying.

Censys says it has seen over 69,000 web-accessible deployments, albeit it may affirm impression from these flaws on solely 130 of them.

Knowledge from The Shadowserver Basis reveals that, as of June 29, 1,289 NetScaler servers weak to CVE-2025–5777 and a couple of,100 cases weak to CVE-2025-6543 have been uncovered to the web.

Given the essential severity of those points and the curiosity menace actors have proven in exploiting Citrix product vulnerabilities, organizations are suggested to patch their NetScaler cases as quickly as potential.

Associated: Citrix Warns of Password Spraying Assaults Focusing on NetScaler Home equipment

Associated: CISA Warns AMI BMC Vulnerability Exploited within the Wild

Associated: Motors Theme Vulnerability Exploited to Hack WordPress Web sites

Security Week News Tags:Citrix, Exploited, Instances, NetScaler, Thousands, Unpatched, Vulnerabilities

Post navigation

Previous Post: Iranian Hackers’ Preferred ICS Targets Left Open Amid Fresh US Attack Warning
Next Post: Django App Vulnerabilities Chained to Execute Arbitrary Code Remotely

Related Posts

RapidFort Secures M to Enhance Software Security Automation RapidFort Secures $42M to Enhance Software Security Automation Security Week News
Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack Security Week News
Ransomware Groups May Shift Back to Encryption Strategies Ransomware Groups May Shift Back to Encryption Strategies Security Week News
Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign Security Week News
Onyx Security Secures  Million to Enhance AI Control Onyx Security Secures $40 Million to Enhance AI Control Security Week News
In-the-Wild Exploitation of Fresh Fortinet Flaws Begins In-the-Wild Exploitation of Fresh Fortinet Flaws Begins Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark