Skip to content
Whats The Hax?Source-backed field notes
← All resources

advisory

NetScaler CVE-2025-5777 advisory brief

A source-checked brief for the customer-managed NetScaler builds affected by CVE-2025-5777, the vendor's fixed builds, and the session-termination step that follows upgrade.

CVE-2025-5777NetScalervulnerability advisory
Published
Sources checked
By
Whats The Hax editorial process

Scope and fixed builds

The vendor describes CVE-2025-5777 as insufficient input validation leading to memory overread when NetScaler is configured as a Gateway or AAA virtual server. The bulletin applies to customer-managed NetScaler ADC and Gateway; it says Citrix-managed cloud services were upgraded by the vendor.

  • NetScaler ADC or Gateway 14.1 before 14.1-43.56 is affected; 14.1-43.56 and later is fixed.
  • NetScaler ADC or Gateway 13.1 before 13.1-58.32 is affected; 13.1-58.32 and later in that branch is fixed.
  • NetScaler ADC 13.1-FIPS or 13.1-NDcPP before 13.1-37.235 is affected; 13.1-37.235 and later in those branches is fixed.
  • NetScaler ADC 12.1-FIPS before 12.1-55.328 is affected; 12.1-55.328 and later in that branch is fixed.
  • Versions 12.1 and 13.0 are end of life and vulnerable; the bulletin directs customers to a supported fixed version.

Response checklist

Inventory every standalone appliance, HA pair, cluster member, and NetScaler instance used by Secure Private Access on-premises or hybrid deployments. Preserve the running build and relevant logs before change where incident handling requires it.

  • Upgrade every member to a fixed build from the official bulletin and verify the running version afterward.
  • After every appliance in the HA pair or cluster is upgraded, follow the bulletin's commands to terminate all active ICA and PCoIP sessions. Copy the commands from the vendor page so formatting and product context are preserved.
  • Review the vendor's linked detection guidance and investigate abnormal access or indicators. If evidence supports exploitation, activate the incident-response process rather than treating upgrade as complete containment.

Limits

This brief summarizes bulletin CTX693420 as checked on 2026-09-07. The vendor says to view the latest bulletin; later builds, deployment modes, detection guidance, or mitigations may change. It does not establish whether any specific appliance was exploited.

Sources

The source-check date records editorial review. Routine builds do not advance it.

Revision history

  • — Initial brief published from NetScaler bulletin CTX693420, including its 2026-07-20 formatting changelog entry.