LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-6543: Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 30, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 21, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-6543 to its Known Exploited Vulnerabilities catalog on Jun 30, 2025, with a federal patch deadline of Jul 21, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA…

CVE-2025-6543 is a buffer overflow vulnerability in Citrix NetScaler ADC and Gateway. When the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, an attacker can trigger the flaw to cause unintended control flow and denial of service. These appliances commonly sit at the network edge for remote access and authentication, so unpatched instances can disrupt availability of critical services. Confirm exact impact and fixed builds against the vendor advisory.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In a buffer overflow of this class, input that exceeds the size of an allocated buffer can overwrite adjacent memory. On NetScaler ADC and Gateway, successful abuse can alter control flow or crash the process, producing a denial-of-service condition. The CISA summary states the vulnerability is reachable only when the device is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; other configurations are outside the documented scope. Specific exploit mechanics, required packets, or authentication requirements are not provided in the public summary and must be confirmed against the vendor advisory. No ransomware use is documented for this CVE.

Am I affected? How to find it in your systems

Citrix NetScaler ADC and Gateway appliances are typically deployed as reverse proxies, SSL VPN gateways, ICA/HDX proxies for Citrix Virtual Apps and Desktops, or AAA authentication front-ends. Inventory every NetScaler instance in your environment—physical, virtual, or cloud-hosted—and record its firmware version and feature configuration.

If you operate NetScaler as a managed cloud service, also follow any applicable BOD 22-01 guidance for cloud services.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions published for CVE-2025-6543. After installing the fixed build, verify that the appliance reports the new version and that Gateway and AAA virtual servers continue to function as expected. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Once patched, harden the remaining attack surface for this class of memory-safety issues:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited edge vulnerabilities can lead to broader compromise even when the primary impact is denial of service. Review logs for signs of successful abuse, rotate any credentials that may have been handled by the appliance, and examine adjacent systems for lateral movement. You can run a free exposure scan of your email address to check whether it appears in known breach data sets and take further steps if matches are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · NetScaler ADC and Gateway
WeaknessCWE-119
Added to CISA KEVJun 30, 2025
Federal patch deadlineJul 21, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities