Desk live·
ForensicPost
Cloud/Exploitation/File 25-0624

CitrixBleed 2 NetScaler Flaw CVE-2025-5777 Widely Exploited From June

A NetScaler memory-disclosure flaw designated CVE-2025-5777 was widely exploited from June 2025. The naming — CitrixBleed 2 — records that this had happened before.

Constructed geometry · not a chart of case data
TargetNetScaler appliances
ActorMultiple
D. Kennedy11 min readConfidence: high2 sources reviewed

CVE-2025-5777, affecting NetScaler ADC and Gateway, was exploited from June 2025 onward, alongside CVE-2025-6543. Researchers named it CitrixBleed 2 in reference to a preceding vulnerability of the same class in the same product line.

The Number In The Nickname Is The Finding

Assigning a sequel name is an editorial judgement by the research community that a defect is not merely similar to an earlier one but recognisably the same mistake in the same place.

Memory disclosure from a remote-access appliance leaks whatever happens to be adjacent — session tokens, credentials, request contents. It bypasses authentication entirely, because the material it returns is what authentication produces.

The Appliance Is The Wrong Shape For The Job

A remote-access gateway is, by definition, the most exposed device an organisation operates and the one holding the most valuable transient material. It is also, typically, a closed appliance: a vendor-controlled image the customer cannot inspect, instrument or independently harden.

The customer’s entire security posture for that device reduces to installing updates promptly and trusting the vendor’s engineering. There is no defence in depth available, which is why this product category recurs throughout the corpus — 25-0814 for SonicWall, 25-0109 for Ivanti, and this file.

Security Appliances Are Software

The uncomfortable observation the corpus keeps producing is that the devices sold to secure a network are among the most reliable sources of compromise in it. That is not vendor incompetence so much as arithmetic: put a complex parser on the internet, in front of everything, and it will have the defects complex parsers have.

The security appliance concentrates risk in exactly the way the concentration files describe, and it does so inside the perimeter it was bought to defend.

How we reported this

Compiled from vendor advisories and public research, listed below. Victim counts are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Lessons from 2025: zero-day exploitation shaping 2026Outpost24
  2. Vulnerability report for the year 2025Vulnerability-Lookup
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary