Citrix has issued patches for a critical memory overflow vulnerability (CVE-2025-6543) affecting NetScaler ADC and Gateway, which could lead to DoS and control flow issues. The vulnerability impacts supported and discontinued versions, prompting urgent updates to prevent exploitation. #CVE-2025-6543 #CitrixBleed2
Keypoints
- The CVE-2025-6543 flaw is a critical memory overflow in NetScaler ADC and Gateway.
- Exploitation of the flaw can cause denial-of-service and unauthorized control flow.
- Patches are available for supported versions, but discontinued versions remain vulnerable.
- This vulnerability follows a recent zero-day (CVE-2025-5777) known as CitrixBleed2.
- Organizations are advised to upgrade, patch, and terminate active sessions to mitigate risks.
Read More: https://www.securityweek.com/critical-citrix-netscaler-flaw-exploited-as-zero-day/