Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    Ad Tech Briefing: A mid-term report card

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025
    • Crypto

      Metaplanet Reports FY2025 Results as Bitcoin Unrealized Losses Top $1 Billion

      February 17, 2026

      Crypto’s AI Pivot: Hype, Infrastructure, and a Two-Year Countdown

      February 17, 2026

      The RWA War: Stablecoins, Speed, and Control

      February 17, 2026

      Jeffrey Epstein Emails Show Plans to Meet Gary Gensler To Talk Crypto

      February 17, 2026

      Bitcoin Bounce Fades, Q1 Losses Deepen, and New Price Risk Back in Focus

      February 17, 2026
    • Technology

      In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

      February 17, 2026

      ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

      February 17, 2026

      Ad Tech Briefing: A mid-term report card

      February 17, 2026

      AdCP vs. IAB Tech Lab: Inside programmatic advertising’s agentic AI standards showdown

      February 17, 2026

      ChatGPT enters the ad game. Now what?

      February 17, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now
    Technology

    Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now

    TechAiVerseBy TechAiVerseJuly 8, 2025No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now

    Researchers have released proof-of-concept (PoC) exploits for a critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed CitrixBleed2, warning that the flaw is easily exploitable and can successfully steal user session tokens.

    The CitrixBleed 2 vulnerability, which affects Citrix NetScaler ADC and Gateway devices, allows attackers to retrieve memory contents simply by sending malformed POST requests during login attempts.

    This critical flaw is named CitrixBleed2 as it closely resembles the original CitrixBleed (CVE-2023-4966) bug from 2023, which was exploited by ransomware gangs and in attacks on governments to hijack user sessions and breach networks.

    In technical analyses first released by watchTowr and then Horizon3, researchers confirmed that the vulnerability can be exploited by sending an incorrect login request, where the login= parameter is modified so it’s sent without an equal sign or value.

    This causes the NetScaler appliance to display the memory contents up to the first null character in the section of the response, as shown below.

    Reading data from memory with a malformed NetScaler login request
    Source: WatchTowr

    The flaw is caused by the use of the snprintf function along with a format string containing the %.*s format string.

    “The %.*s format tells snprintf: “Print up to N characters, or stop at the first null byte (\0) – whichever comes first.” That null byte eventually appears somewhere in memory, so while the leak doesn’t run indefinitely, you still get a handful of bytes with each invocation,” explains watchTowr’s report.

    “So, every time you hit that endpoint without the =, you pull more uninitialized stack data into the response.”

    According to Horizon3, each request leaks approximately 127 bytes of data from data, allowing attackers to perform repeated HTTP requests to extract additional memory contents until they find the sensitive data they are looking for.

    While the attempts by WatchTowr were unsuccessful, Horizon3 demonstrates in the video below that they could exploit this flaw to steal user session tokens.

    In addition to NetScaler endpoints, Horizon3 states that the flaw can also be exploited against configuration utilities used by administrators.

    Exploited or not?

    Citrix continues to state that the flaw is not actively being exploited, and when BleepingComputer previously inquired about its status, the company referred us to a blog post about the vulnerability.

    “Currently, there is no evidence to suggest exploitation of CVE-2025-5777,” reads the blog post.

    However, a June report by cybersecurity firm ReliaQuest indicates that there is evidence that CVE-2025-5777 may have been exploited in attacks, with the company seeing an increase in user session hijacks.

    Furthermore, security researcher Kevin Beaumont disputes Citrix’s statement, saying the vulnerability has been actively exploited since mid-June, with attackers leveraging the bug to dump memory and hijack sessions.

    He highlighted the following indicators of compromise:

    • In Netscaler logs, repeated POST requests to *doAuthentication* – each one yields 126 bytes of RAM
    • In Netscaler logs, requests to doAuthentication.do with “Content-Length: 5”
    • In Netscaler user logs, lines with *LOGOFF* and user = “*#*” (i.e. # symbol in the username). RAM is played into the wrong field.

    “Worth noting I was only able to find exploitation activity due to the WatchTowr and Horizon3 write ups,” warned Beaumont.

    “Citrix support wouldn’t disclose any IOCs and incorrectly claimed (again — happened with CitrixBleed) that no exploitation [was] in the wild. Citrix have gotta get better at this, they’re harming customers.”

    Citrix has released patches to address CVE-2025-5777, and all organizations are strongly urged to apply them immediately now that public exploits are available.

    While Citrix recommends terminating all active ICA and PCoIP sessions, administrators should first review existing sessions for any suspicious activity before doing so.

    8 Common Threats in 2025

    While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

    Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleEmployee gets $920 for credentials used in $140 million bank heist
    Next Article Alleged Chinese hacker tied to Silk Typhoon arrested for cyberespionage
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    February 17, 2026

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    February 17, 2026

    Ad Tech Briefing: A mid-term report card

    February 17, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025681 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025263 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025155 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025114 Views
    Don't Miss
    Technology February 17, 2026

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinksAfter…

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    Ad Tech Briefing: A mid-term report card

    AdCP vs. IAB Tech Lab: Inside programmatic advertising’s agentic AI standards showdown

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    In Graphic Detail: Subscriptions are rising at big news publishers – even as traffic shrinks

    February 17, 20263 Views

    ‘An influential seat at the table’: Why Target’s retail media business Roundel is one of the first to test ChatGPT ads

    February 17, 20262 Views

    Ad Tech Briefing: A mid-term report card

    February 17, 20260 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.