
- CitrixBleed 2 was discovered in mid-June 2025
- But there were quickly reports of abuse in the wild
- CISA is now urging FCEB agencies to patch immediately
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CitrixBleed 2 to its Known Exploited Vulnerabilities (KEV) catalog, alerting Federal Civilian Branch Agencies (FCEB), as well as other businesses, that the bug is being actively exploited in the wild.