CVE-2025-7776: Citrix NetScaler Application Delivery Controller

Critical severity, CVSS 9.8. EPSS: 8.2% chance of exploitation in the next 30 days.

Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it

Affected products

  • Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.330 (fixed in 12.1-55.330); from 13.1, before 13.1-37.241 (fixed in 13.1-37.241); from 13.1, before 13.1-59.22 (fixed in 13.1-59.22); from 14.1, before 14.1-47.48 (fixed in 14.1-47.48)
  • Citrix NetScaler Gateway: from 13.1, before 13.1-59.22 (fixed in 13.1-59.22); from 14.1, before 14.1-47.48 (fixed in 14.1-47.48)

Published 2025-08-26. Last modified 2026-06-17.