{"id":5275,"date":"2025-07-11T10:01:43","date_gmt":"2025-07-11T10:01:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/11\/hackers-actively-exploiting-citrixbleed-2-vulnerability-in-the-wild\/"},"modified":"2025-07-11T10:01:43","modified_gmt":"2025-07-11T10:01:43","slug":"hackers-actively-exploiting-citrixbleed-2-vulnerability-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/11\/hackers-actively-exploiting-citrixbleed-2-vulnerability-in-the-wild\/","title":{"rendered":"Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild"},"content":{"rendered":"<p>    Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Researchers have observed widespread exploitation attempts targeting a critical memory disclosure vulnerability in Citrix NetScaler devices, designated as CVE-2025-5777 and dubbed \u201c<a href=\"https:\/\/cybersecuritynews.com\/citrixbleed-2-poc-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">CitrixBleed 2<\/a>.\u201d\u00a0<\/p>\n<p>This pre-authentication flaw enables attackers to craft malicious requests that leak uninitialized memory from affected NetScaler ADC and Gateway devices, potentially exposing sensitive data, including session tokens, passwords, and configuration values.\u00a0<\/p>\n<p>The vulnerability has prompted immediate security responses from organizations worldwide, with over 200,000 scanning attempts detected within days of the proof-of-concept disclosure.<\/p>\n<pre class=\"wp-block-preformatted\"><strong>Key Takeaways<\/strong><br>1. CVE-2025-5777 affects Citrix NetScaler devices, allowing unauthenticated attackers to leak sensitive memory data including session tokens and passwords.<br>2. Over 200,000 scanning attempts were detected targeting vulnerable endpoints, indicating widespread threat actor activity.<br>3. Attackers send crafted requests with large User-Agent headers to trigger continuous memory leaks from the same target.<br>4. Organizations must immediately patch affected NetScaler versions and implement Akamai's protective rules due to public exploit availability.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>CitrixBleed 2 Vulnerability (CVE-2025-5777)<\/strong><\/h2>\n<p>The CitrixBleed 2 vulnerability stems from improper memory handling in the authentication function of Citrix NetScaler devices.\u00a0<\/p>\n<p>The flaw exploits an uninitialized login variable combined with inadequate input validation and missing error handling in the authentication logic.\u00a0<\/p>\n<p>Since the underlying code is written in C\/C++, which doesn\u2019t automatically initialize variables, attackers can access random stack memory containing leftover data from previous operations.<\/p>\n<p>The vulnerability affects multiple NetScaler versions, including <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-citrix-netscaler-adc-and-gateway\/\" target=\"_blank\" rel=\"noreferrer noopener\">NetScaler ADC and Gateway<\/a> 14.1 before 14.1-43.56, version 13.1 before 13.1-58.32, NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.235-FIPS, and NetScaler ADC 12.1-FIPS before 12.1-55.328-FIPS.\u00a0<\/p>\n<p>The attack targets the URL path \/p\/u\/doAuthentication.do and requires no authentication, making it particularly accessible to threat actors.<\/p>\n<p>Attackers exploit this vulnerability through a systematic approach involving reconnaissance, enumeration, and repeated exploitation attempts.\u00a0<\/p>\n<p>The attack begins with scanning for exposed Citrix NetScaler instances, followed by version verification to identify vulnerable targets.\u00a0<\/p>\n<p>The actual exploit involves sending crafted POST requests to the \/p\/u\/doAuthentication.do endpoint with an unusually large User-Agent header containing recognizable patterns.<\/p>\n<p>The technique earned the \u201c<a href=\"https:\/\/cybersecuritynews.com\/citrix-warns-kill-active\/\" target=\"_blank\" rel=\"noreferrer noopener\">CitrixBleed<\/a>\u201d moniker because attackers can repeatedly trigger memory leaks by sending identical payloads, with each attempt exposing new chunks of stack memory.\u00a0<\/p>\n<p>The oversized User-Agent header injects distinctive markers like \u201cTHR-WAF-RESEARCH\u201d into the stack, which subsequently appear within &lt;InitialValue&gt; XML tags in HTTP responses, confirming successful memory disclosure and revealing sensitive information.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Risk Factors<\/strong><\/td>\n<td><strong>Details<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Affected Products<\/td>\n<td>\u2013 NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-43.56- NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-58.32- NetScaler ADC 13.1-FIPS and NDcPP BEFORE 13.1-37.235-FIPS and NDcPP- NetScaler ADC 12.1-FIPS BEFORE 12.1-55.328-FIPS<\/td>\n<\/tr>\n<tr>\n<td>Impact<\/td>\n<td>Memory disclosure of uninitialized stack memory<\/td>\n<\/tr>\n<tr>\n<td>Exploit Prerequisites<\/td>\n<td>\u2013 No authentication required (pre-authentication flaw)- Network access to target NetScaler device- Ability to send HTTP POST requests- Target endpoint: \/p\/u\/doAuthentication.do- No prior conditions or special privileges needed<\/td>\n<\/tr>\n<tr>\n<td>CVSS 3.1 Score<\/td>\n<td>7.5 (High)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Mitigation Measures<\/strong><\/h2>\n<p>Akamai\u2019s security team has responded to the threat by releasing Rapid Rule 3000967 through their App &amp; API Protector platform.<\/p>\n<p>Initially deployed with an \u201cAlert\u201d action on July 7, 2025, the rule was upgraded to \u201cDeny\u201d status the following day after validation.<\/p>\n<p>Security researchers observed significant scanning activity beginning July 8, 2025, with over 200,000 POST requests targeting the vulnerable endpoint across multiple hostnames and IP addresses.\u00a0<\/p>\n<p>This large-scale scanning represents organized attempts to identify vulnerable NetScaler instances for potential exploitation.\u00a0<\/p>\n<p>Organizations are strongly advised to patch affected devices immediately and implement additional monitoring for indicators of compromise, as the vulnerability\u2019s pre-authentication nature and public <a href=\"https:\/\/cybersecuritynews.com\/ivanti-endpoint-manager-vulnerabilities-proof-of-concept-poc-exploit-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">proof-of-concept<\/a> availability create substantial risk exposure.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt; <a href=\"https:\/\/any.run\/demo?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=red_flags&amp;utm_content=demo&amp;utm_term=070725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a>\u00a0<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/citrixbleed-2-vulnerability-exploited\/\">Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/citrixbleed-2-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild Researchers have observed widespread exploitation attempts targeting a critical memory disclosure vulnerability in Citrix NetScaler devices, designated as CVE-2025-5777 and dubbed \u201cCitrixBleed 2.\u201d\u00a0 This pre-authentication flaw enables attackers to craft malicious requests that leak uninitialized memory from affected NetScaler ADC and Gateway devices, potentially exposing sensitive [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-5275","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5275"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5275"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5275\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}