Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/over-3-000-netscaler-devices-left-unpatched-against-actively-exploited-citrixbleed-2-flaw/
ONE SENTENCE SUMMARY:
Over 3,300 Citrix NetScaler devices remain vulnerable to critical security flaws, risking unauthorized access and data breaches despite available patches.
MAIN POINTS:
- Over 3,300 Citrix NetScaler devices are still unpatched against CVE-2025-5777.
- CVE-2025-5777 enables attackers to bypass authentication by hijacking user sessions.
- The vulnerability allows unauthorized access to sensitive data like session tokens and credentials.
- PoC exploits for CVE-2025-5777 were released shortly after the flaw’s disclosure.
- CVE-2025-6543 is another critical unpatched vulnerability causing denial-of-service attacks.
- NCSC reported attacks on critical organizations in the Netherlands exploiting CVE-2025-6543.
- Advanced threat actors actively exploited the vulnerabilities as zero-days.
- CISA mandates federal agencies to secure against these vulnerabilities quickly.
- The Openbaar Ministerie experienced a breach due to these vulnerabilities.
- The Picus Blue Report 2025 highlights a significant rise in cracked passwords.
TAKEAWAYS:
- Unpatched Citrix devices pose significant risks of unauthorized access and data breaches.
- Early PoC exploits exacerbate the threat posed by CVE-2025-5777.
- CVE-2025-6543 remains a major concern, actively exploited since early May.
- Federal mandates emphasize the urgency of securing vulnerable systems.
- Rising password breaches indicate a growing need for stronger cybersecurity measures.