CVE-2025-6543: Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
CSIRTS triage
- What
- This vulnerability is a buffer overflow leading to denial of service.
- Who is affected
- Deployments of Citrix NetScaler ADC and Gateway configured as specified are affected.
- Urgency
- Remediation is critical due to active exploitation and the severity of the vulnerability.
- Action
- Apply the latest security updates from Citrix.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch NetScaler ADC and Gateway
Get an email when a new NetScaler ADC and Gateway advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-6543
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2025-6543Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 95% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-6543 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedMultiple vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (July 1, 2025)cert-fr-alerte
Recent advisories for Citrix NetScaler ADC
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Citrix Systems NetScaler (Gateway and ADC): Multiple vulnerabilitiescert-bund · 2026-08-20
- unknownNCSC-2026-0318 [1.00] [M/M] Vulnerabilities resolved in Citrix NetScaler ADC and NetScaler Gatewayncsc-nl · 2026-08-20
- critical2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gatewaycert-eu · 2026-08-19
- unknownNCSC-2026-0216 [1.01] [M/H] Vulnerabilities Fixed in Citrix Netscaler ADC and Netscaler Gatewayncsc-nl · 2026-08-18
- high[UPDATE] [high] Citrix Systems NetScaler ADC and Gateway: Multiple vulnerabilitiescert-bund · 2026-07-02
- unknownNCSC-2026-0216 [1.00] [M/H] Vulnerabilities fixed in Citrix Netscaler ADC and Netscaler Gatewayncsc-nl · 2026-06-30
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-60004: Gitea Code Injection Vulnerability2026-08-25
- criticalCVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerabil…2026-08-24
- criticalCVE-2026-73570: Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability2026-08-21
- criticalCVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability2026-08-20
- criticalCVE-2026-72530: TrueConf Server Code Injection Vulnerability2026-08-20