{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/netscaler-adc-14.1--14.1-12.39/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Citrix NetScaler / ADC","SimpleHelp RMM","Fortinet EMS","NetScaler ADC 14.1 (\u003c 14.1-12.39)","NetScaler ADC 13.1 (\u003c 13.1-51.15)","NetScaler ADC 13.0 (\u003c 13.0-93.19)","NetScaler ADC 12.1 (\u003c 12.1-66.25)","NetScaler Gateway 14.1 (\u003c 14.1-12.39)","NetScaler Gateway 13.1 (\u003c 13.1-51.15)","NetScaler Gateway 13.0 (\u003c 13.0-93.19)","NetScaler Gateway 12.1 (\u003c 12.1-66.25)"],"_cs_severities":["high"],"_cs_tags":["citrixbleed2","memory-disclosure","web-application"],"_cs_type":"advisory","_cs_vendors":["Citrix","SimpleHelp","Fortinet"],"content_html":"\u003cp\u003eCVE-2025-5777, also known as CitrixBleed 2, is a memory disclosure vulnerability affecting Citrix NetScaler ADC and Gateway appliances. This vulnerability allows an unauthenticated attacker to potentially leak sensitive information, including session tokens and authentication credentials, from the device's memory. The attack involves sending specially crafted POST requests with incomplete form data to the \u003ccode\u003e/p/u/doAuthentication.do\u003c/code\u003e endpoint. Successful exploitation can lead to unauthorized access to internal resources and systems, posing a significant risk to organizations using affected Citrix products. The vulnerability was publicly disclosed in March 2026 (fictional date based on the source). Defenders should prioritize detecting and mitigating this vulnerability to prevent potential data breaches and unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a vulnerable Citrix NetScaler ADC or Gateway appliance exposed to the internet.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious POST request with incomplete form data targeting the \u003ccode\u003e/p/u/doAuthentication.do\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker sends the crafted POST request to the vulnerable Citrix appliance.\u003c/li\u003e\n\u003cli\u003eThe vulnerable appliance processes the request, leading to a memory leak.\u003c/li\u003e\n\u003cli\u003eThe response from the Citrix appliance contains sensitive data from memory, including session tokens and potentially authentication credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker captures the leaked data from the response.\u003c/li\u003e\n\u003cli\u003eThe attacker analyzes the captured data to extract valid session tokens.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the stolen session tokens to bypass authentication and gain unauthorized access to internal resources and systems.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-5777 can result in significant data breaches and unauthorized access to sensitive internal resources. An attacker can steal valid session tokens, bypassing authentication mechanisms, and potentially gain complete control over affected Citrix systems. This could lead to the exposure of customer data, intellectual property, and other confidential information. The impact can range from data theft and service disruption to full system compromise, depending on the scope of the attacker's access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eCitrixBleed2_Post_Request\u003c/code\u003e to detect suspicious POST requests to the \u003ccode\u003e/p/u/doAuthentication.do\u003c/code\u003e endpoint in your web server logs.\u003c/li\u003e\n\u003cli\u003eInvestigate alerts triggered by the \u003ccode\u003eCitrixBleed2_UserAgent\u003c/code\u003e Sigma rule, focusing on unusual user agents making requests to the vulnerable endpoint.\u003c/li\u003e\n\u003cli\u003eEnsure your Citrix NetScaler ADC and Gateway devices are patched to the latest version to mitigate CVE-2025-5777, as recommended in the Citrix advisory.\u003c/li\u003e\n\u003cli\u003eMonitor Suricata logs for traffic matching the \u003ccode\u003esuricata_citrixbleed2.log\u003c/code\u003e attack data provided in the test section to validate detection coverage.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T04:04:39Z","date_published":"2024-01-03T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2024-01-citrixbleed2/","summary":"Exploitation of CVE-2025-5777 (CitrixBleed 2) in Citrix NetScaler ADC and Gateway leads to memory disclosure by sending crafted POST requests to the /p/u/doAuthentication.do endpoint, potentially leaking session tokens and authentication materials.","title":"CitrixBleed 2 Memory Disclosure via CVE-2025-5777","url":"https://feed.craftedsignal.io/briefs/2024-01-citrixbleed2/"}],"language":"en","title":"CraftedSignal Threat Feed - NetScaler ADC 14.1 (\u003c 14.1-12.39)","version":"https://jsonfeed.org/version/1.1"}