<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

CitrixBleed 2 and Cisco Zero-Day Exploits Hit Organizations Before Patches Released

APT group exploits Citrix and Cisco zero-days before patches, highlighting risks in identity management systems. Learn how to protect your edge devices.
Content Team

Amazon's threat intelligence team discovered that sophisticated attackers exploited two critical vulnerabilities as zero-days before vendors issued patches. The unnamed advanced persistent threat (APT) group targeted CitrixBleed 2 (CVE-2025-5777) in Citrix NetScaler systems and a maximum-severity bug (CVE-2025-20337) in Cisco Identity Service Engine for a month before disclosure.

The CitrixBleed 2 flaw allows attackers to hijack admin sessions and join any NetScaler session, while the Cisco vulnerability enables remote code execution as root. Amazon observed the same attackers hitting both systems simultaneously, deploying custom web shells designed to remain hidden in memory.

This "patch-gap" exploitation technique highlights how advanced threat actors target identity and access management infrastructure. Organizations should assume edge devices are vulnerable, implement blast radius reduction, and shift from patch-centric to exposure-centric security approaches.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo