Citrix Bleed Two is a zero-day exploitation campaign impacting Citrix appliances and related Cisco/Citrix infrastructure, used by APT actors to remotely compromise exposed devices.
Citrix Bleed Two is a vulnerability tracked across 5 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity November 13, 2025.
Citrix Bleed Two is a zero-day exploitation campaign impacting Citrix appliances and related Cisco/Citrix infrastructure, used by APT actors to remotely compromise exposed devices. It is notable for active exploitation across multiple products, prompting urgent patching and heightened monitoring by defenders.
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
Cisco has disclosed critical vulnerabilities in its Unified Contact Center Express (CCX) platform and Adaptive Security Appliances (ASA) that allow unauthenticated remote attackers to execute arbitrary code and…
Cisco has reported ongoing attacks against its firewalls, specifically targeting vulnerabilities CVE-2025-20333 and CVE-2025-20362. These flaws allow remote code execution and unauthorized access, leading to potential…
Citrix Bleed Two is a zero-day exploitation campaign impacting Citrix appliances and related Cisco/Citrix infrastructure, used by APT actors to remotely compromise exposed devices.
The most recent intelligence report mentioning Citrix Bleed Two on ThreatCluster is dated November 13, 2025. Activity was first observed November 12, 2025, giving a tracked span from then to November 13, 2025.
Across ThreatCluster reporting, Citrix Bleed Two most frequently co-occurs with APT-C-08, Bitter, Manlinghua, Malware, Zero-day Exploit, among 12 tracked related entities.
The most significant recent cluster is “Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities” (8 articles · Updated November 12, 2025). Citrix Bleed Two appears across 5 threat clusters in total, listed above with sources.
Citrix Bleed Two appears in 4 intelligence report mentions across 5 deduplicated threat clusters, aggregated from 17,000+ monitored sources.