⚠ Actively exploited
Added to CISA KEV on 2025-08-26. Federal agencies required to patch by 2025-08-28. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2025-7775Improper Restriction of Operations within the Bounds of a Memory Buffer in ADC

Severity
9.2CRITICALNVD
EPSS
6.6%
top 8.83%
CISA KEV
KEV
Added 2025-08-26
Due 2025-08-28
Exploit
No known exploits
Timeline
PublishedAug 26
KEV addedAug 26
KEV dueAug 28
Latest updateMar 28
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Affected Packages11 packages

CVEListV5netscaler/gateway14.147.48+3
NVDcitrix/netscaler_gateway13.113.1-59.22+1
CVEListV5netscaler/adc14.147.48+3

🔴Vulnerability Details

2
GHSA
GHSA-2m4h-vp37-6746: Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is confi2025-08-26
VulnCheck
Citrix NetScaler Memory Overflow Vulnerability2025

📋Vendor Advisories

2
CISA
Citrix NetScaler Memory Overflow Vulnerability2025-08-26
Citrix
Citrix Security Bulletin CTX694938

🕵️Threat Intelligence

32
Hackernews
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug2026-03-28
Hackernews
Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks2026-03-24
Bleepingcomputer
Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws2025-09-03
Bleepingcomputer
Over 28,000 Citrix devices vulnerable to new exploited RCE flaw2025-08-27
Bleepingcomputer
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks2025-08-26