Cybersecuritydive CitrixBleed 2 Exploited by Initial Access Broker for DragonForce Ransomware Attacks
Article Content
- •CVE-2025-5777 (CitrixBleed 2) exploited in multiple attacks during early 2026.
- •Attackers used privilege escalation and rogue accounts to deploy DragonForce ransomware.
- •Organizations using Citrix NetScaler are urged to patch their systems immediately.
In the first half of 2026, multiple organizations were targeted by an Initial Access Broker exploiting the CitrixBleed 2 vulnerability (CVE-2025-5777). Attackers gained access through the Citrix NetScaler gateway, escalating privileges and creating rogue administrator accounts. The most advanced attack led to the deployment of DragonForce ransomware, with rapid execution leaving little time for defenders to respond. Huntress identified a consistent attack pattern across at least six incidents, prompting warnings for organizations to patch their systems. The vulnerability was linked to insufficient input validation in NetScaler ADC and Gateway configurations. Sophos also tracked the cluster of attacks under the name STAC3725, noting similarities to previous incidents involving QEMU tooling. Citrix had released guidance on the vulnerability in 2025.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2023-4966 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…