CVE-2025-5777, affecting NetScaler ADC and Gateway, was exploited from June 2025 onward, alongside CVE-2025-6543. Researchers named it CitrixBleed 2 in reference to a preceding vulnerability of the same class in the same product line.
The Number In The Nickname Is The Finding
Assigning a sequel name is an editorial judgement by the research community that a defect is not merely similar to an earlier one but recognisably the same mistake in the same place.
Memory disclosure from a remote-access appliance leaks whatever happens to be adjacent — session tokens, credentials, request contents. It bypasses authentication entirely, because the material it returns is what authentication produces.
The Appliance Is The Wrong Shape For The Job
A remote-access gateway is, by definition, the most exposed device an organisation operates and the one holding the most valuable transient material. It is also, typically, a closed appliance: a vendor-controlled image the customer cannot inspect, instrument or independently harden.
The customer’s entire security posture for that device reduces to installing updates promptly and trusting the vendor’s engineering. There is no defence in depth available, which is why this product category recurs throughout the corpus — 25-0814 for SonicWall, 25-0109 for Ivanti, and this file.
Security Appliances Are Software
The uncomfortable observation the corpus keeps producing is that the devices sold to secure a network are among the most reliable sources of compromise in it. That is not vendor incompetence so much as arithmetic: put a complex parser on the internet, in front of everything, and it will have the defects complex parsers have.
The security appliance concentrates risk in exactly the way the concentration files describe, and it does so inside the perimeter it was bought to defend.
Compiled from vendor advisories and public research, listed below. Victim counts are not established. Corrections: corrections@forensicpost.com.
- Lessons from 2025: zero-day exploitation shaping 2026Outpost24
- Vulnerability report for the year 2025Vulnerability-Lookup