Citrix ‘Bleed 2’ Flaw Joins CISA Exploited List
The U.S. Cybersecurity and Infrastructure Security Agency added the Citrix Bleed 2 flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation in the wild. Tracked as CVE-2025-5777, the vulnerability affects Citrix NetScaler ADC and Gateway products configured as VPN or AAA virtual servers, allowing unauthenticated attackers to steal session cookies and bypass multi-factor authentication. […]
