What breaks and who should care
If your environment runs a Citrix NetScaler ADC or Gateway, the scanner has just flagged CVE-2025-5777. This is not a theoretical issue – it is a high‑severity out‑of‑bounds read that can be triggered by specially crafted traffic to a VPN, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server. Anyone responsible for the appliance – whether you are a sysadmin on‑call, a security engineer, or a manager of the service – needs to know whether the flaw applies to you and what to do right now.
Related remediation guides
Other vulnerabilities in the same family or affecting the same products:
- CVE-2025-1094 – PostgreSQL libpq quoting injection – quick guide
- CVE-2025-22225 – VMware ESXi arbitrary write vulnerability – what you need to know at 2 am
- CVE-2025-26399 – Immediate actions for SolarWinds Web Help Desk
We keep a daily-updated list of vulnerabilities CISA has confirmed as actively exploited, including remediation deadlines.
Technical description
The vulnerability is an out‑of‑bounds memory read caused by insufficient input validation. In plain English, the NetScaler component that handles traffic for the listed virtual server types does not correctly check the length of a field in the incoming request. An attacker can supply data that is longer than the buffer expects, causing the appliance to read beyond the intended memory region. The read itself does not corrupt memory, but it can expose bits of internal data to the attacker. In the worst‑case scenario, the leaked data can be combined with other weaknesses to achieve code execution or to aid ransomware payloads – something CISA has already observed in the wild.
The exact packet structure and the precise offset that triggers the overread are not publicly disclosed. Citrix has classified the flaw as an out‑of‑bounds read, which places it in the same family as classic buffer‑overread bugs. The impact is therefore information disclosure, and because the data resides in memory that may contain authentication tokens or configuration details, the practical risk can be significant.
How bad is it really?
CVSS rates it at 7.5, which puts it solidly in the high category. The rating reflects the ease of exploitation – a remote attacker only needs to send a crafted request to a vulnerable virtual server – and the potential impact of the data that can be leaked. CISA has added CVE-2025-5777 to its Known Exploited Vulnerabilities catalog and notes that ransomware groups have used it as an entry point. That means you are not just looking at a paper‑thin advisory; real‑world actors are already weaponising the flaw.
In practice, the severity you experience depends on three factors:
- Presence of a vulnerable virtual server. If you run only standard web or load‑balancing vservers, you may be safe, but any VPN, ICA Proxy, CVPN, RDP Proxy, or AAA vserver brings the risk.
- Network exposure. An appliance that is reachable from the internet is a far more attractive target than one locked behind a zero‑trust zone.
- Data sensitivity. If the appliance stores or proxies credentials, session tokens, or internal configuration in memory, the leaked bytes could be valuable to an attacker.
Given the confirmed exploitation and the ransomware link, the recommendation is to treat this as an urgent issue.
Determining whether you are affected
The first step is to verify the software version running on each NetScaler ADC or Gateway you manage. Log in to the appliance’s CLI and run:
show version
The output will display the product name, the release branch (for example, 12.1, 13.1, 14.1), and the exact build identifier. Compare that identifier against the table below – the table lists the last vulnerable build for each branch and the first patched build. If your build appears in the vulnerable range, you are exposed.
Next, confirm whether any of the vulnerable virtual server types are configured. Use the following command to list all vservers and their types:
show run vserver
Look for entries that include “VPN”, “ICA Proxy”, “CVPN”, “RDP Proxy” or “AAA”. If you see any, those vservers are potential attack vectors.
Finally, check your network exposure. If the appliance’s management IP or the virtual server IPs are reachable from untrusted networks, you need to act quickly. If they are fully firewalled, you still need to patch, but you have a little more time to schedule a maintenance window.
Mitigation and remediation steps
Citrix’s official guidance is to upgrade to the patched release for your branch. The table below shows which releases contain the fix. Apply the upgrade as soon as you can – the process is the same as any other NetScaler firmware update.
Step‑by‑step remediation:
- Back up the current configuration. Use
save configand export the configuration file to a secure location. - Download the appropriate patched image. Obtain it from Citrix’s support portal, selecting the image that matches your release branch.
- Upload the image to the appliance. The CLI command
install ns image_namewill place the new firmware on the device. - Reboot into the new image. A simple
rebootwill complete the upgrade. - Validate the upgrade. After reboot, run
show versionagain to confirm the new build identifier appears. - Test critical services. Verify that VPN, ICA Proxy, CVPN, RDP Proxy and AAA functions operate as expected.
If you run a high‑availability pair, repeat the process on the secondary node first, then fail over and upgrade the primary. This minimises downtime.
While the upgrade is the definitive fix, Citrix also supplies a temporary mitigation for environments that cannot patch immediately. The mitigation involves disabling the vulnerable virtual server types or restricting them to trusted IP ranges via an ACL. For example, you can add an access control list that only permits internal management subnets to reach the VPN vserver:
add ns acl vpn_acl -srcIP 10.0.0.0/8
bind ns vserver vpn_vs -aclName vpn_acl -policyName allow
Remember, this is a stop‑gap. The ACL does not eliminate the flaw; it merely reduces the attack surface by limiting who can send traffic to the vulnerable service.
If a patched release is unavailable
In the unlikely event that you cannot obtain the patched image – perhaps because you are locked onto an older branch that Citrix no longer supports – you have two options:
- Isolate the appliance. Move it to a network segment that is not reachable from the internet or from any untrusted zone. Block all inbound traffic to the vulnerable virtual servers at the perimeter firewall.
- Disable the vulnerable services. Use the CLI to shut down the specific vservers. For example:
disable ns vserver vpn_vs
disable ns vserver ica_proxy_vs
After isolation or disabling, you must still plan a migration to a supported version. Running an unsupported, unpatched product is a liability that will only grow over time.
Compliance and reporting
CISA’s directive requires you to apply mitigations per vendor instructions, follow the BOD 22‑01 guidance for cloud services if you are using NetScaler in a cloud‑hosted scenario, or discontinue use if you cannot mitigate. Document the steps you have taken – version check, vserver inventory, mitigation applied, upgrade schedule – and retain the logs for audit purposes.
Because the vulnerability is listed in the Known Exploited Vulnerabilities catalog, many compliance frameworks will flag any unpatched instance as a failure. Treat the remediation as a compliance requirement as well as a security one.
What to do after the fix
Once the patched image is running, re‑run your vulnerability scanner to confirm the issue is cleared. Keep an eye on Citrix security advisories for any follow‑up patches. It’s also a good time to review your overall NetScaler hardening guide – ensure that only the necessary virtual server types are enabled, that management interfaces are locked down, and that logging is sent to a central SIEM.
Finally, consider adding the show version check to your regular health‑check scripts. Automating the version verification will catch future regressions before they become a problem.
References
- Citrix Security Advisory for CVE-2025-5777 (official vendor guidance)
- CISA Known Exploited Vulnerabilities catalog entry for CVE-2025-5777
- National Vulnerability Database entry for CVE-2025-5777
Version table
The table below lists the affected and fixed releases for each NetScaler branch. Use it to confirm whether your current build is vulnerable.
Affected versions
Straight from the NVD record for CVE-2025-5777. If your build is inside one of these ranges, treat it as vulnerable.
| Product | Affected range | Fixed in |
|---|---|---|
netscaler_application_delivery_controller |
12.1 up to 12.1-55.328 | 12.1-55.328 |
netscaler_application_delivery_controller |
13.1 up to 13.1-37.235 | 13.1-37.235 |
netscaler_application_delivery_controller |
13.1 up to 13.1-58.32 | 13.1-58.32 |
netscaler_application_delivery_controller |
14.1 up to 14.1-43.56 | 14.1-43.56 |
netscaler_gateway |
13.1 up to 13.1-58.32 | 13.1-58.32 |
netscaler_gateway |
14.1 up to 14.1-43.56 | 14.1-43.56 |


