{"cve":{"cve_id":"CVE-2025-7775","is_kev":true,"kev_date_added":"2025-08-26","kev_vendor_project":"Citrix","kev_product":"NetScaler","kev_vulnerability_name":"Citrix NetScaler Memory Overflow Vulnerability","kev_short_description":"Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.","kev_required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","kev_due_date":"2025-08-28","kev_known_ransomware":false,"kev_notes":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938 ; https://nvd.nist.gov/vuln/detail/CVE-2025-7775","kev_cwes":["CWE-119"],"epss_score":0.18973,"epss_percentile":0.96932,"epss_as_of":"2026-06-23","description":"Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server\n\n(OR)\n\nNetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers \n\n(OR)\n\nNetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers\n\n(OR)\n\nCR virtual server with type HDX","published_at":"2025-08-26T12:56:53.794000Z","last_modified_at":null,"cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":9.2,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L","cvss_v4_severity":"CRITICAL","ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-119"],"nvd_references":["https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-06-28T23:28:33.297624Z"},"effective_severity":"CRITICAL","badges":["kev"],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"H","value_label":"High"},{"metric":"AT","name":"Attack Requirements","value":"P","value_label":"Present"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"H","value_label":"High"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"L","value_label":"Low"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"L","value_label":"Low"},{"metric":"SA","name":"Availability (Subsequent System)","value":"L","value_label":"Low"}]},"affected":[{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"adc","product_name":"ADC","version_start":"14.1","version_start_inclusive":true,"version_end":"47.48","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:adc:14.1:47.48"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"adc","product_name":"ADC","version_start":"13.1","version_start_inclusive":true,"version_end":"59.22","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:adc:13.1:59.22"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"adc","product_name":"ADC","version_start":"13.1 FIPS and NDcPP","version_start_inclusive":true,"version_end":"37.241","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:adc:13.1 FIPS and NDcPP:37.241"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"adc","product_name":"ADC","version_start":"12.1 FIPS and NDcPP","version_start_inclusive":true,"version_end":"55.330","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:adc:12.1 FIPS and NDcPP:55.330"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"gateway","product_name":"Gateway","version_start":"14.1","version_start_inclusive":true,"version_end":"47.48","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:gateway:14.1:47.48"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"gateway","product_name":"Gateway","version_start":"13.1","version_start_inclusive":true,"version_end":"59.22","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:gateway:13.1:59.22"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"gateway","product_name":"Gateway","version_start":"13.1 FIPS and NDcPP","version_start_inclusive":true,"version_end":"37.241","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:gateway:13.1 FIPS and NDcPP:37.241"},{"vendor_slug":"netscaler","vendor_name":"NetScaler","product_slug":"gateway","product_name":"Gateway","version_start":"12.1 FIPS and NDcPP","version_start_inclusive":true,"version_end":"55.330","version_end_inclusive":false,"cpe23_uri":"cve5:netscaler:gateway:12.1 FIPS and NDcPP:55.330"}],"exploit_refs":[],"news":[],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938","source_type":"MISC","tags":[]}],"timeline":[{"type":"cisa_reported","at":"2025-08-26T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"published","at":"2025-08-26T12:56:53.794000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:49:50.811184Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:49:50.811184Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:49:50.811184Z","label":"CVSS score revised","source":"cvelistv5"}]}