Known vulnerability record

CVE-2025-5777

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Stable IDcve:CVE-2025-5777Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

Keep the signals separate

CVSS severitycriticalScore 9.3 · source Citrix
EPSS probability100.0%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-07-10
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-06-17
CVE modified
2026-08-04
KEV date added
2025-07-10
Dataset fetched
2026-08-21T03:55:05.238Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.