Overview
What is CVE-2025-5777?
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
CISA lists CVE-2025-5777 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Citrix NetScaler ADC and Gateway.
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server