07.07.2025

Critical vulnerabilities in Citrix NetScaler – active attacks observed

In recent weeks, several serious security vulnerabilities have been discovered in Citrix NetScaler ADC and Gateway – some of them known as “CitrixBleed 2”. Although the vulnerabilities have already been fixed by the manufacturer, experts classify them as critical .

IT security researchers report active attacks in which, among other things, existing web sessions were compromised and authentications were obtained without the knowledge of the users – suggesting that active multi-factor authentication could also be bypassed.

What happened?

Currently, CERT.at and numerous email security vendors are seeing an increase in phishing campaigns that use email attachments in Scalable Vector Graphics (SVG) format. These vector graphics contain embedded JavaScript code that can be executed from the browser when opened. Attackers use this to load fake login pages or install malware – with the aim of grabbing access data. The affected SVG files often disguise themselves as invoices, voice messages, or documents to be signed.

Reported vulnerabilities
(Source:
BSI)

Who is affected?

  • NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-47.46
  • NetScaler ADC and NetScaler Gateway 13.1 prior to 13.1-59.19
  • NetScaler ADC 13.1-FIPS and NDcPP prior to 13.1-37.236-FIPS and NDcPP
  • NetScaler ADC 12.1-FIPS prior to 12.1-55.328-FIPS (not affected by CVE-2025-6543)

How can I protect myself?

1. Install security updates (urgently!)

Immediately install the patches provided by the manufacturer:

  • 14.1-47.46 or newer
  • 13.1-59.19 or newer
  • 13.1-37.236-FIPS/NDcPP or newer


2. Check the configuration

  • Allow access to the management interface only from trusted networks.
  • Disable unnecessary services and interfaces.

3. Monitor systems

  • Enable logging and intrusion detection.
  • Monitor suspicious activity (e.g., unusual session behavior, failed logins).

What exactly does the Citrix Netscaler ADC do?

Citrix NetScaler ADC (Application Delivery Controller) is a system that enables secure, fast, and reliable access to web applications – even under heavy loads. It is widely used in enterprises for load balancing, performance optimization, and security.