CVE-2025-6543
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 July 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- CVSS 4.0
- 9.2 CRITICALCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 10.09% probability · 95th percentile
- CISA KEV
- Listed 30 June 2025 · due 21 July 2025
- Weakness
- CWE-119
- Affected
- citrix/netscaler application delivery controller · citrix/netscaler gateway
- Source
- secure@citrix.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788 ; https://www.netscaler.com/blog/news/netscaler-critical-security-updates-for-cve-2025-6543-and-cve-2025-5777/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-6543
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.