CVE-2025-7776
9.8
CRITICAL · CVSS 3.1 · EPSS 8.1% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.15% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-08-26 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| citrix | netscaler application delivery controller |
| citrix | netscaler gateway |
→ the Explorer · watch your stack · NVD