Citrix.NetScaler.ADC.Gateway.startwebview.Out-of-Bounds.Read

description-logoDescription

This indicates an attack attempt to exploit an Out-of-Bounds Read Vulnerability in Citrix NetScaler ADC and NetScaler Gateway.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted request. A remote attacker can exploit this to gain unauthorized access to sensitive information.

description-logoOutbreak Alert

FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28, 2025. Telemetry indicates activity has surged to over 6,000 detections across IPS sensors globally. The majority of observed attacks are concentrated in the United States, Australia, Germany, and the United Kingdom, with adversaries primarily focusing on high-value sectors such as technology, banking, healthcare, and education.

View the full Outbreak Alert Report

affected-products-logoAffected Products

Citrix NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-43.56
Citrix NetScaler ADC and NetScaler Gateway 13.1 prior to 13.1-58.32
Citrix NetScaler ADC 13.1-FIPS and NDcPP prior to 13.1-37.235-FIPS and NDcPP
Citrix NetScaler ADC 12.1-FIPS prior to 12.1-55.328-FIPS

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-07-30 33.055
Modified
Default_action:pass:drop
2025-07-29 33.054
Modified
Sig Added
2025-07-10 33.043
New