VulnerabilitiesCritical

Citrix and Cisco ISE Zero-Days Exploited by Advanced Threat Actor

Tuesday, March 17, 2026
Global
BleepingComputer

Summary

Critical vulnerabilities Citrix Bleed 2 (CVE-2025-5777) in NetScaler ADC/Gateway and CVE-2025-20337 in Cisco ISE exploited as zero-days to deploy custom malware. Cisco flaw allows unauthenticated attackers to gain root privileges.

Threat Analysis

Critical vulnerabilities Citrix Bleed 2 (CVE-2025-5777) in NetScaler ADC/Gateway and CVE-2025-20337 in Cisco ISE exploited as zero-days to deploy custom malware. Cisco flaw allows unauthenticated attackers to gain root privileges. This incident highlights the evolving threat landscape and the sophisticated tactics employed by modern threat actors. Organizations should review their security posture, ensure all systems are patched, implement defense-in-depth strategies, and monitor for indicators of compromise. Source: BleepingComputer

Last updated: Mar 17, 2026, 09:23 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM