CVE-2025-5777
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- Published Jun 17, 2025
- CVSS 9.3 critical
- 100.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
Affected software
In the news
- APT and financial attacks on industrial organizations in Q2 2026 Kaspersky ICS CERT ·