CitrixBleed is a vulnerability tracked by ThreatCluster, appearing in 7 threat clusters built from 8 intelligence report mentions.
CitrixBleed is a vulnerability tracked across 7 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity July 25, 2026.
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
Citrix disclosed six high-severity vulnerabilities in NetScaler ADC and Gateway appliances, including CVE-2026-8451, which allows unauthenticated memory disclosure when configured as a SAML identity provider. Other…
A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a…
Amazon reported that a threat actor is exploiting two critical vulnerabilities, CVE-2025-20337 and CVE-2025-5777, in Cisco ISE and Citrix products as zero-days. These vulnerabilities have been identified as being…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
Amazon has identified an advanced threat actor exploiting zero-day vulnerabilities in Cisco Identity Service Engine (ISE) and Citrix NetScaler. The attackers utilized CVE-2025-20337 and CVE-2025-5777 to deploy custom…
CitrixBleed is a vulnerability tracked by ThreatCluster, appearing in 7 threat clusters built from 8 intelligence report mentions.
The most recent intelligence report mentioning CitrixBleed on ThreatCluster is dated July 25, 2026. Activity was first observed November 12, 2025, giving a tracked span from then to July 25, 2026.
Across ThreatCluster reporting, CitrixBleed most frequently co-occurs with Armored Likho, Data Breach, DDoS, Malware, Phishing, among 12 tracked related entities.
The most significant recent cluster is “Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities” (8 articles · Updated November 12, 2025). CitrixBleed appears across 7 threat clusters in total, listed above with sources.
CitrixBleed appears in 8 intelligence report mentions across 7 deduplicated threat clusters, aggregated from 17,000+ monitored sources.