Netscaler News Articles

Recent news articles refferecing the vendors vulnerabilities.

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Attackers wasted little time targeting the latest memory disclosure bug in Citrix NetScaler, after researchers published a proof-of-concept exploit.

2 weeks ago

CitrixBleed Vulnerability Exploitation Within 24 Hours of Disclosure - IT Security News

Citrix NetScaler appliances are currently facing significant threats due to the rapid exploitation of a newly disclosed memory disclosure vulnerability, CVE-2026-8451, which is part of the evolving “CitrixBleed” class. This high-severity flaw (CVSS 8.8), disclosed on June 30, 2026, in…Read more →

3 weeks ago

CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure

A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure.

3 weeks ago

NetScaler Memory Overread Flaw Echoes CitrixBleed

A new NetScaler memory overread bug, CVE-2026-8451, leaks process data and revives CitrixBleed fears. Here is what admins need to patch and why it matters.

3 weeks ago

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

Hackers began exploiting vulnerability CVE-2026-8451 in Citrix NetScaler ADC and NetScaler Gateways less than 24 hours after disclosure.

3 weeks ago

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

Security updates fix six NetScaler ADC and Gateway vulnerabilities, including 8.8-rated DoS bugs and unauthenticated file read.

3 weeks ago

Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

Citrix has patched five NetScaler ADC and NetScaler Gateway vulnerabilities, including a high-severity defect similar to CitrixBleed.

3 weeks ago

Citrix patches a new NetScaler flaw with echoes of CitrixBleed

Citrix patched six NetScaler flaws, headlined by a high-severity memory disclosure bug (CVE-2026-8451) with striking similarities to CitrixBleed.

3 weeks ago

CVE-2026-8451: Citrix NetScaler Vulnerability Leaks Memory  | eSecurity Planet

CVE-2026-8451 is a Citrix NetScaler vulnerability that can leak process memory through specially crafted SAML requests.

3 weeks ago

Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug

CVE-2026-3055 targets Citrix NetScaler with active reconnaissance, risking data leaks on SAML IDP setups.

‘Advanced’ hacker seen exploiting Cisco, Citrix zero-days

The hackers notably used custom malware and were exploiting CVE-2025-5777 — now known colloquially as “Citrix Bleed Two” — before it was disclosed publicly in July.

ThreatsDay Bulletin: Cisco 0-Days, AI Bug Bounties, Crypto Heists, State-Linked Leaks and 20 More Stories

Global cyber roundup: new AI bug bounties, malware threats, GDPR backlash, Cisco zero-days, data leaks, and rising attacks on key infrastructure.

Amazon Uncovers CVE-2025-20337 & CVE-2025-5777 Exploits

Amazon reports APTs exploiting CVE-2025-20337 and CVE-2025-5777 zero-day flaws in Cisco and Citrix systems.

Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101)

There’s an elegance to vulnerability research that feels almost poetic - the quiet dance between chaos and control. It’s the art of peeling back the layers of complexity, not to destroy but to understand; to trace the fragile threads that hold systems together and see where they might

Amazon: Cisco, Citrix 0-days indicate 'advanced' attacker

An "advanced" attacker exploited CitrixBleed 2 and a max-severity Cisco Identity Services Engine (ISE) bug as zero-days to deploy custom malware, according to Amazon Chief Information Security Officer CJ...

Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws

Amazon reports dual zero-day exploits in Cisco ISE and Citrix ADC used to deploy custom malware.

Amazon discovers APT exploiting Cisco and Citrix zero-days | Amazon Web Services

The Amazon threat intelligence team has identified an advanced threat actor exploiting previously undisclosed zero-day vulnerabilities in Cisco Identity Service Engine (ISE) and Citrix systems. The campaign used custom malware and demonstrated access to multiple undisclosed vulnerabilities. This dis...

NetScaler ADC and Gateway Vulnerable: Urgent Updates to Prevent XSS Attacks

NetScaler has issued a security bulletin for an XSS vulnerability affecting its NetScaler ADC and NetScaler Gateway products. Urgent updates are recommended.

Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws

Hackers are increasingly using a new AI-powered offensive security framework called HexStrike-AI in real attacks to exploit newly disclosed n-day flaws.

Over 28,000 Citrix devices vulnerable to new exploited RCE flaw

More than 28,200 Citrix instances are vulnerable to a critical remote code execution vulnerability tracked as CVE-2025-7775 that is already being exploited in the wild.

Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks

Citrix fixed three NetScaler ADC and NetScaler Gateway flaws today, including a critical remote code execution flaw tracked as CVE-2025-7775 that was actively exploited in attacks as a zero-day vulnerability.

Citrix Under Active Attack Again with Another Zero-Day

The flaw is one of three the company disclosed affecting its NetScaler ADC and NetScaler Gateway technologies.

Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775

Citrix patches CVE-2025-7775 exploited in NetScaler ADC; fixes three flaws with no workarounds.

Pennsylvania attorney general's email, site down after cyberattack

The Office of the Pennsylvania Attorney General has announced that a recent cyberattack has taken down its systems, including landline phone lines and email accounts.

Over 3,000 NetScaler devices left unpatched against CitrixBleed 2 bug

Over 3,300 Citrix NetScaler devices remain unpatched against a critical vulnerability that allows attackers to bypass authentication by hijacking user sessions, nearly two months after patches were released.

No more news articles to load.