The National Cyber Security Center (NCSC) recently made available two scripts that allow organizations to check for themselves whether their Citrix systems have been attacked. The scripts have been published on GitHub.
The checkscripts contain new indicators of compromise. These were discovered as a result of recent NCSC forensic investigations.
"If forensic investigation using the check scripts is not performed (in a timely manner), there is a chance that compromise of systems will go undetected and the malicious actor will retain access," the NCSC warns. Organizations that believe their Citrix systems have been hacked are urged to contact the NCSC.
The Shadowserver Foundation conducted an online scan. It showed that more than 3,300 systems were not updated for CVE-2025-5777. More than 4,200 systems are vulnerable to attacks via CVE-2025-6543. The platform Binnenlands Bestuur recently wrote that security vulnerabilities in Citrix systems are straining the security of thousands of organizations, including vital Dutch organizations.
Click here for the NCSC's message.