A Citrix NetScaler out-of-bounds read given a next-day due date — one day against a median grace period of 21
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability caused by insufficient input validation, which can lead to memory overread when configured as a Gateway or AAA virtual server. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-07-10 with a due date of 2025-07-11 — one day later. Use in ransomware campaigns is known.
Key facts
- CVE IDCVE-2025-5777
- Affected (vendor / product)Citrix NetScaler ADC and Gateway
- CWECWE-125
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2025-07-11 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Citrix NetScaler ADC and Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation.
- Memory overread can occur when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
- Added to KEV on 2025-07-10 with a due date of 2025-07-11 — a one-day grace period. Use in ransomware campaigns is known.
- Across the 1,687 records this site holds as of 2026-09-02, grace periods have a median of 21 days and a maximum of 184; one day is the shortest.
- The required action is mitigations per vendor instructions, BOD 22-01 guidance for cloud services, or discontinuing use.
1An unusual one-day grace period
Every entry in the CISA Known Exploited Vulnerabilities catalog carries a due date by which federal agencies are to complete remediation. Across the 1,687 records this site holds as of 2026-09-02, the grace period from the date added to the due date has a median of 21 days and a maximum of 184. What this entry received was the shortest possible: one day. Remediate by tomorrow.
2Where it falls in the distribution
The length of a due date reads as a judgment reflecting the state of exploitation and the difficulty of remediation. A median of 21 days sits roughly within a monthly patch cycle. A one-day due date means acting without waiting for the next scheduled window.
3What gets read out
The class of fault here is an out-of-bounds read: the program reads memory past the region it allocated. Unlike a write it does not directly execute code, but whatever happened to be sitting in that region leaves in the response. If values used for authentication are among them, that alone becomes a foothold.
The condition applies when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
4The character of a device on the perimeter
A VPN gateway is placed as the single door from outside into the internal network. Being a door, it must be reachable from the internet, and authentication material flows through it. This record also notes that use in ransomware campaigns is known. The required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use. Verify applicability with official vendor information and your own environment.
Why it matters
A one-day due date means a monthly patch cycle will not be fast enough. A VPN gateway on the perimeter is reachable from the internet by design and carries authentication material, which makes having an emergency application procedure ready in advance the relevant preparation.
FAQ
Is an out-of-bounds read less serious than a write?
How is a due date decided?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).