CVE-2025-7775 – Memory Overflow in Citrix NetScaler ADC/Gateway (Zero-Day RCE)

ISGroup Cybersecurity

CVE-2025-7775 is a critical zero-day memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway—specifically in configurations involving VPN, AAA, IPv6 balancing, or HDX virtual servers. It allows for unauthenticated remote code execution (RCE) and/or denial-of-service (DoS). The vulnerability is already being actively exploited and has a CVSS 4.0 score of 9.2 (Critical). Citrix states that there are no mitigations other than applying the patch.

U.S. federal agencies are required to apply the patch by August 28, 2025, following the inclusion of the vulnerability in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

ProductCitrix-NetScaler
Date2025-08-28 09:33:43
Information
  • Fix Available
  • Active Exploitation

Technical Summary

Vulnerability Type: Memory overflow vulnerability (CWE-119) in NetScaler ADC and Gateway.
Exploitability:

  • Remote exploitation—no authentication or user interaction required.
  • High severity—active attacks have been observed.
    Limited configurations affected: Only appliances configured as Gateway, AAA virtual server, IPv6-bound LB virtual servers (HTTP, SSL, HTTP_QUIC), or CR servers with HDX.
    Impact:
  • Confidentiality: Potential full system compromise via RCE.
  • Integrity & Availability: Service disruption or installation of backdoors. Affected versions:
  • NetScaler ADC/Gateway 14.1 prior to 14.1-47.48
  • 13.1 prior to 13.1-59.22
  • 13.1-FIPS/NDcPP prior to 13.1-37.241
  • 12.1-FIPS/NDcPP prior to 12.1-55.330

Recommendations

  1. Apply patches immediately
  • Update to the corrected versions:
    • 14.1-47.48 or later
    • 13.1-59.22 or later
    • 13.1-37.241 (FIPS/NDcPP) or later
    • 12.1-55.330 (FIPS/NDcPP) or later

  1. Check configurations
  • Verify ns.conf for roles such as Gateway, AAA, IPv6 LB virtual server, or HDX CR server to assess exposure.
  1. Isolate vulnerable devices
  • If patching is not immediately possible, limit exposure by isolating affected NetScaler appliances from the internet.
  1. Monitor for suspicious activity
  • Examine logs for indicators such as unauthorized shell access or anomalous RCE attempts.
  • Incident response activity is recommended, as the exploit has already been observed.
  1. Adopt a Defense-in-Depth strategy
  • Ensure that management interfaces (NSIP, etc.) are not accessible from the internet.
  • Implement network segmentation and robust access control mechanisms.
  1. Stay updated on related vulnerabilities
  • CVE-2025-7776 (another memory overflow) and CVE-2025-8424 (improper access control) are included in the same advisory—ensure they are covered by your patching process.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert