<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Citrix Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Citrix.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More</title><link>https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.html</link><guid isPermaLink="false">cst-2414</guid><description>A weekly security recap highlights multiple threats including ShareFile vulnerabilities, Citrix Bleed 2 ransomware activity, and AI-powered coding attacks. The piece emphasizes that while security tools automate vulnerability discovery, attackers similarly leverage automation to find and exploit weaknesses, and many organizations remain unpatched against known issues from prior years.</description><pubDate>Mon, 13 Jul 2026 15:05:57 GMT</pubDate></item><item><title>Citrix launches MCP Gateway to secure enterprise AI agents</title><link>https://helpnetsecurity.com/2026/07/09/citrix-mcp-gateway</link><guid isPermaLink="false">cst-2259</guid><description>Citrix announced new MCP Gateway functionality for its NetScaler platform that enables enterprises to securely route, govern, and observe traffic to Model Context Protocol servers. The update also includes enhancements to NetScaler AI Gateway for improved model routing and token-level usage tracking on large language model traffic.</description><pubDate>Thu, 09 Jul 2026 13:49:56 GMT</pubDate></item><item><title>CitrixBleed-ing Again? NetScaler Vulnerability Under Attack</title><link>https://darkreading.com/vulnerabilities-threats/citrixbleed-ing-again-netscaler-vulnerability-under-attack</link><guid isPermaLink="false">cst-490</guid><description>A new memory disclosure vulnerability in Citrix NetScaler products is being actively exploited by attackers following the release of a proof-of-concept exploit by researchers. The flaw allows unauthorized access to sensitive data stored in memory.</description><pubDate>Mon, 06 Jul 2026 21:17:42 GMT</pubDate></item><item><title>6th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/6th-july-threat-intelligence-report-2</link><guid isPermaLink="false">cst-594</guid><description>A threat intelligence bulletin reports multiple significant incidents across sectors: ransomware attacks affecting financial, defense, manufacturing, and insurance organizations; artificial intelligence threats including LLM-generated ransomware, unsafe coding agents, and phishing domain hijacking; and critical vulnerabilities in Oracle, Linux, Citrix, and Progress products with active exploitation observed.</description><pubDate>Mon, 06 Jul 2026 12:01:54 GMT</pubDate></item><item><title>Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials</title><link>https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html</link><guid isPermaLink="false">cst-33</guid><description>Anubis ransomware operators are exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to targets. The group employs common tactics including legitimate Remote Management and Monitoring tools, credential harvesting, and manual lateral movement techniques.</description><pubDate>Thu, 02 Jul 2026 18:30:33 GMT</pubDate></item><item><title>Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service</title><link>https://thehackernews.com/2026/07/citrix-patches-six-netscaler-flaws.html</link><guid isPermaLink="false">cst-56</guid><description>Citrix released security updates on Tuesday addressing six vulnerabilities in NetScaler ADC and NetScaler Gateway, including flaws that could allow arbitrary file reads or denial-of-service attacks. The vulnerabilities stem from issues such as insufficient input validation, with at least one flaw rated at CVSS 8.8.</description><pubDate>Wed, 01 Jul 2026 03:54:22 GMT</pubDate></item><item><title>CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)</title><link>https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451</link><guid isPermaLink="false">cst-555</guid><description>Citrix has publicly disclosed CVE-2026-8451, a memory overread vulnerability in NetScaler devices that allows unauthenticated access to sensitive information. This marks another instance in a recurring pattern of memory disclosure vulnerabilities affecting NetScaler appliances, which the researcher refers to as part of the broader CitrixBleed class of issues. The vulnerability demonstrates ongoing memory management weaknesses in a critical appliance used for load balancing, SSL termination, and remote access across enterprise networks.</description><pubDate>Tue, 30 Jun 2026 19:35:58 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item><item><title>You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 &amp; CVE-2026-2701)</title><link>https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701</link><guid isPermaLink="false">cst-561</guid><description>Researchers discovered and chained two vulnerabilities in Progress ShareFile's Storage Zone Controller (an on-premises gateway managing file transfers) to achieve unauthenticated remote code execution. The flaws, CVE-2026-2699 (authentication bypass) and CVE-2026-2701 (remote code execution), affected version 5.12.3 on the ASP.NET branch and were patched in version 5.12.4 released March 10, 2026. Approximately 30,000 Storage Zone Controller instances are exposed on the internet.</description><pubDate>Thu, 02 Apr 2026 10:00:42 GMT</pubDate></item><item><title>A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)</title><link>https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746</link><guid isPermaLink="false">cst-562</guid><description>A 32-year-old pre-authentication remote code execution vulnerability (CVE-2026-32746) was discovered in GNU inetutils Telnetd by the DREAM Security Research Team. The BSS-based buffer overflow exists in the LINEMODE SLC negotiation handler and affects multiple operating systems and distributions that derive from the same codebase, including Ubuntu, Debian, FreeBSD, NetBSD, and others. Despite the severity and wide impact, the vulnerability had received minimal public analysis at the time of reporting.</description><pubDate>Thu, 19 Mar 2026 20:21:07 GMT</pubDate></item><item><title>Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public</title><link>https://greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc</link><guid isPermaLink="false">cst-1895</guid><description>GreyNoise detected active exploitation of CVE-2025-5777, a memory overread vulnerability in Citrix NetScaler, starting June 23, approximately two weeks before a public proof-of-concept was publicly released on July 4. This indicates attackers had access to exploitation knowledge or techniques ahead of public disclosure.</description><pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate></item><item><title>Critical vulnerabilities in NetScaler ADC exploited in-the-wild: everything you need to know</title><link>https://wiz.io/blog/critical-vulnerabilities-netscaler-adc-exploited-in-the-wild-cve-2025-5777</link><guid isPermaLink="false">cst-1448</guid><description>Three critical vulnerabilities affecting Citrix NetScaler ADC and Gateway devices are being actively exploited in the wild. Organizations should apply patches immediately to mitigate the identified CVEs (2025-5349, 2025-5777, and 2025-6543).</description><pubDate>Sun, 06 Jul 2025 12:45:49 GMT</pubDate></item><item><title>Netscaler Exploitation to Social Engineering | Huntress</title><link>https://huntress.com/blog/netscaler-exploitation-to-social-engineering-mapping-convergence-of-adversary-tradecraft-across-victims</link><guid isPermaLink="false">cst-1035</guid><description>Huntress team analyzed recent intrusions linked to Netscaler exploitation, examining the attack chain and techniques used by threat actors. The analysis documents how attackers leveraged the vulnerability to establish initial access and conduct follow-on operations.</description><pubDate>Tue, 26 Sep 2023 00:00:00 GMT</pubDate></item><item><title>CVE-2022-27518 exploited in the wild by APT5: everything you need to know</title><link>https://wiz.io/blog/cve-2022-27518-exploited-in-the-wild-by-apt5-everything-you-need-to-know</link><guid isPermaLink="false">cst-1766</guid><description>CVE-2022-27518 is an unauthenticated remote code execution vulnerability affecting Citrix ADC and Gateway that has been exploited in active attacks by the nation state actor APT5. Organizations running affected Citrix products face immediate risk and should prioritize patching.</description><pubDate>Tue, 13 Dec 2022 21:03:18 GMT</pubDate></item></channel></rss>