CVE-2025-5777: Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-07-10. EPSS: 100% chance of exploitation in the next 30 days.

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Affected products

  • Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.328 (fixed in 12.1-55.328); from 13.1, before 13.1-37.235 (fixed in 13.1-37.235); from 13.1, before 13.1-58.32 (fixed in 13.1-58.32); from 14.1, before 14.1-43.56 (fixed in 14.1-43.56)
  • Citrix NetScaler Gateway: from 13.1, before 13.1-58.32 (fixed in 13.1-58.32); from 14.1, before 14.1-43.56 (fixed in 14.1-43.56)

Published 2025-06-17. Last modified 2026-10-08.