peter bassill · operator
$ cve CVE-2025-5777 JSON

CVE-2025-5777 KEV EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-07-11.

Description

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS99.97% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-125
On CISA KEVyes — remediate by 2025-07-11
Public exploityes
Published2025-06-17
Last modified2026-08-04

CISA KEV

NameCitrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Added2025-07-10
Due2025-07-11
Vendor / productCitrix / NetScaler ADC and Gateway
Ransomware useknown

Affected (2)

VendorProduct
citrixnetscaler application delivery controller
citrixnetscaler gateway

Public exploits

SourceTitleDate
exploit-dbCitrix NetScaler ADC/Gateway 14.1 - Memory Disclosure2025-08-11

References

→ the Explorer  ·  watch your stack  ·  NVD