Over 28,000 Citrix instances remain exposed to critical RCE flaw CVE-2025-7775

Over 28,000 Citrix instances remain exposed to critical RCE flaw CVE-2025-7775

Over 28,200 Citrix NetScaler ADC/Gateway instances remain exposed to critical RCE flaw CVE-2025-7775, already under active exploitation.

Experts at the Shadowserver Foundation warn that more than 28,200 Citrix instances are vulnerable to the vulnerability CVE-2025-7775, which is under active exploitation.

CVE-2025-7775(CVSS score: 9.2) is a memory overflow vulnerability leading to Remote Code Execution and/or Denial-of-Service.

This week,Citrixaddressedthree security flaws (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424) in NetScaler ADC and NetScaler Gateway, including one (CVE-2025-7775) that it said has been actively exploited in the wild.

“Exploits of CVE-2025-7775 on unmitigated appliances have been observed.” reads the advisory.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe Citrix NetScalerflaw to itsKnown Exploited Vulnerabilities (KEV) catalog. The US Agency orders federal agencies to fix the vulnerabilities byAugust 28, 2025.

Shadowserver Foundationresearchers reported that most of the vulnerable instances arelocatedin the United States(10,100), followed by Germany (4,300), the United Kingdom (1,400), the Netherlands (1,300), and Switzerland (1,300).

Follow me on Twitter:@securityaffairsandFacebookandMastodon

PierluigiPaganini

(SecurityAffairs–hacking,CVE-2025-7775)