Advisory 95

Advisory 95: Multiple vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products.

Release Date: 26th of August 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations who utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

Multiple vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products.

  • CVE-2025-7775 (Critical) involves a memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service.
  • CVE-2025-7776 (High) involves a memory overflow vulnerability leading to unpredictable or erroneous behaviour and Denial of Service.
  • CVE-2025-8424 (High) involves improper access control on the NetScaler Management Interface.

 

References

  1. https://www.cve.org/CVERecord?id=CVE-2025-7775
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938
  4. https://www.netscaler.com/blog/news/critical-security-update-announced-for-netscaler-gateway-and-netscaler/