Exploited Known exploited (KEV) Ransomware use CVE-2025-5777

A Citrix NetScaler out-of-bounds read given a next-day due date — one day against a median grace period of 21

Citrix NetScaler ADC and Gateway Added to KEV Jul 10, 2025 Federal remediation due 2025-07-11

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability caused by insufficient input validation, which can lead to memory overread when configured as a Gateway or AAA virtual server. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-07-10 with a due date of 2025-07-11 — one day later. Use in ransomware campaigns is known.

Key facts

  • CVE IDCVE-2025-5777
  • Affected (vendor / product)Citrix NetScaler ADC and Gateway
  • CWECWE-125
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2025-07-11 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Citrix NetScaler ADC and Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation.
  • Memory overread can occur when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
  • Added to KEV on 2025-07-10 with a due date of 2025-07-11 — a one-day grace period. Use in ransomware campaigns is known.
  • Across the 1,687 records this site holds as of 2026-09-02, grace periods have a median of 21 days and a maximum of 184; one day is the shortest.
  • The required action is mitigations per vendor instructions, BOD 22-01 guidance for cloud services, or discontinuing use.

1An unusual one-day grace period

Every entry in the CISA Known Exploited Vulnerabilities catalog carries a due date by which federal agencies are to complete remediation. Across the 1,687 records this site holds as of 2026-09-02, the grace period from the date added to the due date has a median of 21 days and a maximum of 184. What this entry received was the shortest possible: one day. Remediate by tomorrow.

2Where it falls in the distribution

Grace period for this entry1 dayAdded 2025-07-10, due 2025-07-11
Median grace period across the records this site holds as of 2026-09-0221 daysAcross 1,687 records
Longest grace period at that date184 daysThe shortest is one day

The length of a due date reads as a judgment reflecting the state of exploitation and the difficulty of remediation. A median of 21 days sits roughly within a monthly patch cycle. A one-day due date means acting without waiting for the next scheduled window.

3What gets read out

The class of fault here is an out-of-bounds read: the program reads memory past the region it allocated. Unlike a write it does not directly execute code, but whatever happened to be sitting in that region leaves in the response. If values used for authentication are among them, that alone becomes a foothold.

The condition applies when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.

4The character of a device on the perimeter

A VPN gateway is placed as the single door from outside into the internal network. Being a door, it must be reachable from the internet, and authentication material flows through it. This record also notes that use in ransomware campaigns is known. The required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use. Verify applicability with official vendor information and your own environment.

Why it matters

A one-day due date means a monthly patch cycle will not be fast enough. A VPN gateway on the perimeter is reachable from the internet by design and carries authentication material, which makes having an emergency application procedure ready in advance the relevant preparation.

FAQ

Is an out-of-bounds read less serious than a write?
It does not directly execute code, but information left in the region beyond the allocation leaves in the response. If authentication material is among it, that alone becomes a foothold.
How is a due date decided?
It is set per KEV entry and reads as a judgment reflecting the state of exploitation and the difficulty of remediation. Across the 1,687 records this site holds as of 2026-09-02, the median is 21 days.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Citrix#VPN#Out-of-bounds read
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.