Critical Citrix NetScaler Flaw Exploited as Zero-Day

Critical Citrix NetScaler Flaw Exploited as Zero-Day

Citrix has issued patches for a critical memory overflow vulnerability (CVE-2025-6543) affecting NetScaler ADC and Gateway, which could lead to DoS and control flow issues. The vulnerability impacts supported and discontinued versions, prompting urgent updates to prevent exploitation. #CVE-2025-6543 #CitrixBleed2

Keypoints

  • The CVE-2025-6543 flaw is a critical memory overflow in NetScaler ADC and Gateway.
  • Exploitation of the flaw can cause denial-of-service and unauthorized control flow.
  • Patches are available for supported versions, but discontinued versions remain vulnerable.
  • This vulnerability follows a recent zero-day (CVE-2025-5777) known as CitrixBleed2.
  • Organizations are advised to upgrade, patch, and terminate active sessions to mitigate risks.

Read More: https://www.securityweek.com/critical-citrix-netscaler-flaw-exploited-as-zero-day/