peter bassill · operator
$ cve CVE-2025-7775 JSON

CVE-2025-7775 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 19.6% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2025-08-28.

Description

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.63% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2025-08-28
Public exploitnone known
Published2025-08-26
Last modified2026-06-17

CISA KEV

NameCitrix NetScaler Memory Overflow Vulnerability
Added2025-08-26
Due2025-08-28
Vendor / productCitrix / NetScaler
Ransomware usenone reported

Affected (2)

VendorProduct
citrixnetscaler application delivery controller
citrixnetscaler gateway

References

→ the Explorer  ·  watch your stack  ·  NVD