← Back to CVE List
Vulnerability Intelligence Report
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread

CVE-2025-5777

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:99.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-125 ↗CWE-125 Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
NetScaler ADC 14.1 < 43.56 (affected), 13.1 < 58.32 (affected)
NetScaler Gateway 14.1 < 43.56 (affected), 13.1 < 58.32 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.959%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCitrix Systems, Inc. · Vendor · USA
Reserved2025-06-06T06:14:02
Published2025-06-17T12:29:34
Patch Date2025-06-17
Last Updated2026-08-04T03:55:49

LINK COPIED TO CLIPBOARD