๐Ÿ”ด CVE-2025-7775

Critical memory overflow vulnerability in NetScaler ADC and Gateway allowing unauthenticated remote code execution. Active zero-day exploitation confirmed against internet-facing appliances with CISA KEV listing.

โ† Back to Overview
HIGH_RISK
Risk Level
T1190
MITRE Technique
9.2
CVSS Score
NETWORK
Attack Vector
VERY_HIGH
Deployment Risk

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-08-26

Added to CISA KEV: 2025-08-26 0 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence

Key Sources:

  • NetScaler ADC/Gateway zero-day exploited by attackers (CVE-2025-7775 ...

    NetScaler has fixed 3 vulnerabilities in its ADC and Gateway devices, one of which (CVE-2025-7775) has been exploited in zero-day attacks.

  • CVE-2025-7775 | Tenableยฎ

    Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or ...

  • Security Bulletin - CITRIX | Support

    Exploits of CVE-2025-7775 on unmitigated appliances have been observed. Cloud Software Group strongly urges affected customers of NetScaler ADC ...

  • NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-7775 ...

    Exploits of CVE-2025-7775 on unmitigated appliances have been observed. Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.

  • CVE-2025-7775 - NVD

    CVE CISA KEV Update by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 8/26/2025 9:00:02 PM