CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2025-5777 (Citrix Bleed 2): Exploited for DragonForce Ransomware Deployment

June 25, 2026

CVE-2025-5777, known as Citrix Bleed 2, is being exploited by threat actors to deploy DragonForce ransomware. Attackers follow a consistent post-compromise pattern including privilege escalation, creation of rogue admin accounts, and use of legitimate remote access tools.