Hackers are actively exploiting a critical vulnerability (CVE-2025-6543) in Citrix NetScaler products, which could allow unauthorized data access and session hijacking. Security experts warn that multiple bugs related to this flaw may be interconnected and pose a significant threat to organizations using affected appliances. #CVE-2025-6543 #CitrixNetScaler #CitrixBleed #RansomwareGangs #CriticalInfrastructure
Keypoints
- The CVE-2025-6543 vulnerability affects Citrix NetScaler ADC and Gateway appliances with a high severity score of 9.2.
- Exploits of the vulnerability have already been observed on unmitigated systems.
- Related bugs (CVE-2025-5349 and CVE-2025-5777) may be connected and could allow attackers to bypass multi-factor authentication.
- Cybersecurity experts compare these bugs to Citrix Bleed, a widely exploited flaw from 2023.
- Organizations such as the NHS and US agencies have expressed concern over the potential impact on critical infrastructure and sensitive data.
Read More: https://therecord.media/citrix-warns-netscaler-exploitation-bug