Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.html
https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
https://thehackernews.com/2026/03/citrix-netscaler-under-active-recon-for.html
https://thehackernews.com/2026/03/citrix-urges-patching-critical.html
https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/
https://www.securityweek.com/cisco-ise-citrixbleed-2-vulnerabilities-exploited-as-zero-days-amazon/
https://www.darkreading.com/vulnerabilities-threats/citrixbleed-2-cisco-zero-day-bugs
https://www.theregister.com/2025/08/28/thousands_of_citrix_netscaler_boxes/
https://www.darkreading.com/vulnerabilities-threats/citrix-zero-day-under-active-attack
https://cyberscoop.com/citrix-netscaler-zero-day-exploited-august-2025/
https://www.securityweek.com/citrixbleed-2-flaw-poses-unacceptable-risk-cisa/
https://www.databreachtoday.com/attackers-now-scanning-extensively-for-citrix-bleed-2-a-28959
https://cyberscoop.com/citrixbleed2-exploits-spread/
https://thehackernews.com/2025/07/cisa-adds-citrix-netscaler-cve-2025.html
https://www.theregister.com/2025/07/10/cisa_citrixbleed_kev/
https://www.securityweek.com/exploits-technical-details-released-for-citrixbleed2-vulnerability/
https://www.databreachtoday.com/attackers-actively-exploit-citrix-bleed-2-vulnerability-a-28907
https://horizon3.ai/attack-research/attack-blogs/cve-2025-5777-citrixbleed-2-write-up-maybe/
https://www.helpnetsecurity.com/2025/06/30/citrixbleed-2-might-be-actively-exploited-cve-2025-5777/
https://www.securityweek.com/evidence-suggests-exploitation-of-citrixbleed-2-vulnerability/
https://www.infosecurity-magazine.com/news/citrixbleed-2-vulnerability/
https://www.theregister.com/2025/06/25/citrix_netscaler_critical_bug_exploited/
https://thehackernews.com/2025/06/citrix-bleed-2-flaw-enables-token-theft.html
https://cyberscoop.com/citrix-zero-day-netscaler/
https://www.theregister.com/2025/06/24/critical_citrix_bug_citrixbleed/
https://doublepulsar.com/citrixbleed-2-electric-boogaloo-cve-2025-5777-c7f5e349d206
https://thehackernews.com/2025/04/critical-ivanti-flaw-actively-exploited.html
https://news.sophos.com/en-us/2025/04/02/2025-sophos-active-adversary-report/
https://services.google.com/fh/files/misc/m-trends-2024.pdf
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-attacks-exploits
https://www.secureworks.com/blog/lockbit-in-action
https://blog.talosintelligence.com/talos-ir-quarterly-report-q4-2023/
https://therecord.media/hhs-warns-of-citrix-bleed-bug
https://cyberplace.social/@GossiTheDog/111502145876827515
https://cybernews.com/news/yanfeng-ransomware-attack-claimed-qilin/
https://www.theregister.com/2025/08/12/major_outage_at_pennsylvania_attorney/
https://isc.sans.edu/diary/rss/30498
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a
https://cyberplace.social/@GossiTheDog/111408758925049114
https://www.theregister.com/2023/10/31/mass_exploitation_citrix_bleed/
https://www.mandiant.com/resources/blog/session-hijacking-citrix-cve-2023-4966
Published: 2023-10-10
Updated: 2026-07-31
Named Vulnerability: CitrixBleedNamed Vulnerability: Citrix BleedKnown Exploited Vulnerability (KEV)
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Severity: High
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.99999
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Concern