← Back to CVE intelligence
CVE intelligenceCISA KEVRansomware use

CVE-2025-5777

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Published Jun 17, 2025Sources checked Sep 12, 2026
7.5HIGHCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2025-5777 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Citrix NetScaler ADC and Gateway.

  • Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA KEVListedObserved exploitation
EPSS100.0%Estimated 30-day exploitation probability
Ransomware useReported by CISACISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2025-5777?

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server