CVE-2025-6543
Published Jun 25, 2025
Last updated 2 months ago
AI description
CVE-2025-6543 is a memory overflow vulnerability found in Citrix NetScaler ADC and NetScaler Gateway. It affects appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. The vulnerability stems from improper restriction of operations within the bounds of a memory buffer. Successful exploitation of CVE-2025-6543 could lead to unintended control flow and a denial-of-service (DoS) condition. Exploits targeting this vulnerability have been observed in the wild, prompting Citrix to release security updates.
- Description
- Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- Source
- secure@citrix.com
- NVD status
- Analyzed
- Products
- netscaler_application_delivery_controller, netscaler_gateway
CVSS 4.0
- Type
- Secondary
- Base score
- 9.2
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
- Exploit added on
- Jun 30, 2025
- Exploit action due
- Jul 21, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- secure@citrix.com
- CWE-119
- Hype score
- Not currently trending
🚨 Urgent! Citrix Netscaler flaw CVE-2025-6543 is ALREADY being exploited in the Netherlands to breach organizations. Patch your systems NOW! #CitrixSecurity #CyberAttack https://t.co/0j6apknLd1
@xcybersecnews
16 Aug 2025
53 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-6543
@transilienceai
16 Aug 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2025-6543
@transilienceai
15 Aug 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Nearly 7,000 Citrix NetScaler appliances vulnerable to critical flaws **CVE-2025-5777** and **CVE-2025-6543**. Remote access, data theft, and disruption of essential services. 🔗 [https://t.co/MpBm1GF3Rw\](https://t.co/Oqi0WELxNX) \#CyberSecurity #Canada #AgencePDN https
@AgencePdn
14 Aug 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Près de 7 000 Citrix NetScaler vulnérables aux failles critiques **CVE-2025-5777** et **CVE-2025-6543**. Accès à distance, vols de données et perturbations de services essentiels. 🔗 [https://t.co/MpBm1GF3Rw\](https://t.co/Oqi0WELxNX) #Cybersécurité #Canada #Agen
@AgencePdn
14 Aug 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The Dutch National Cyber Security Centre (NCSC-NL) has confirmed active cyberattacks targeting CVE-2025-6543, a critical vulnerability (CVSS 9.2) in Citrix NetScaler ADC and NetScaler Gateway. This flaw affects devices configured as a Gateway (VPN, ICA Proxy, CVPN, RDP Proxy) h
@FORTBRIDGE
14 Aug 2025
60 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
NCSC-NL confirms active exploitation of CVE-2025-6543 in Citrix NetScaler across critical Dutch infrastructure
@mahesh0x1
14 Aug 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Citrix NetScaler Zero-Day (CVE-2025-6543) actively exploited since May. Targets VPN/ICA/AAA configs. Attackers gain persistent access, add admins, wipe logs. Patch now, kill sessions, hunt .php shells, review outbound traffic. Assume compromise. https://t.co/VoBIes4
@certcube
13 Aug 2025
59 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Your NetScaler might already be a backdoor 🚨 The Dutch NCSC states that CVE-2025-6543 (CVSS 9.2) has been exploited since May, resulting in web shells, log wiping, and critical sector attacks. 1️⃣ Patch ✅ 2️⃣ Kill sessions ✅ 3️⃣ Hunt IOCs ✅ Treat as c
@secure_blink
13 Aug 2025
48 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/SYz0huowo9
@PVynckier
13 Aug 2025
198 Impressions
5 Retweets
5 Likes
0 Bookmarks
1 Reply
0 Quotes
Active exploitation of CVE-2025-6543 in Citrix NetScaler causes breaches in critical sectors. Erlang/OTP SSH and WinRAR vulnerabilities also targeted by threat actors, impacting multiple systems globally. #NetScaler #WinRAR #Netherlands https://t.co/7Ym6o1tqvR
@TweetThreatNews
13 Aug 2025
119 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors #CISO https://t.co/prkDZeybi7 https://t.co/qKV8QujuxZ
@compuchris
12 Aug 2025
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The Netherlands' National Cyber Security Centre (NCSC) is warning that a critical Citrix NetScaler vulnerability tracked as CVE-2025-6543 was exploited to breach "critical organizations" in the country. https://t.co/HGNCbpzudB
@blackwired32799
12 Aug 2025
61 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors. CVE-2025-6543 (CVSS score: 9.2) is a critical security vulnerability in NetScaler ADC that results in unintended control flow and denial-of-service (DoS). https://t.co/jnQLI6GmDP https
@riskigy
12 Aug 2025
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Over 3,300 Citrix NetScaler devices remain unpatched against critical CVE-2025-5777 and CVE-2025-6543 flaws, enabling session hijacking, MFA bypass, and data theft with active global exploitation reported. #CitrixBleed #CISA #USA https://t.co/P9e0QPAK04
@TweetThreatNews
12 Aug 2025
83 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543) https://t.co/AJc3LGM2Lv #HelpNetSecurity #Cybersecurity https://t.co/b1j2Orzrp4
@PoseidonTPA
12 Aug 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543) https://t.co/UCqwlmdcKN
@TheCyberSecHub
12 Aug 2025
643 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
#Cybersecurity Dutch NCSC Confirms Active Exploitation of #Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/JRStdyScoT
@jos1727
12 Aug 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The CVE-2025-6543 flaw is a silent alarm for everyone. A memory overflow issue in Citrix NetScaler ADC is actively exploited, with a CVSS score of 9.8. Organizations need to PATCH NOW and terminate all sessions to halt any intrusions. https://t.co/N2x4SwMrva
@The4n6Analyst
12 Aug 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch #NCSC Confirms Active Exploitation of Citrix #NetScaler #CVE-2025-6543 in Critical Sectors https://t.co/EBVYY3UfEx
@ScyScan
12 Aug 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/gQukLcGZPA #CyberSecurity
@EpicPlain
12 Aug 2025
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs The Netherlands' National Cyber Security Centre (NCSC) is warning that a critical Citrix NetScaler vulnerability tracked : https://t.co/96sTTnQMAh #blog #digitpatrox
@DigitpatroxOff
12 Aug 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
IN 🇳🇱 Hackers exploited critical vulnerability Cve-2025-6543 in Citrix NetscalerHaving broken several key organizations, including the prosecutor's office. Zero-Day used over 2️⃣ months before the patch. Citrix advises urgently updating the software and check the system
@Hack_Your_Mom
12 Aug 2025
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix Vulnerability CVE-2025-6543 Exploited In Attacks #CISO https://t.co/6XZHAHPgcU
@compuchris
12 Aug 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Hollanda Ulusal Siber Güvenlik Merkezi (NCSC-NL), Citrix NetScaler ADC ürünlerini etkileyen kritik bir güvenlik açığının (CVE-2025-6543) aktif olarak sömürüldüğüne dair önemli bir uyarı yayınladı. https://t.co/NUjf4c2Fhl
@et2mas
12 Aug 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Alerta de Segurança: A falha crítica CVE-2025-6543 no Citrix NetScaler já está sendo explorada contra setores estratégicos na Holanda. O bug, ativo como zero-day por dois meses antes da divulgação, permite controle remoto e negação de serviço. Admins, é hora de at
@TechStartXYZ
12 Aug 2025
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
APT-style attacks exploited CVE-2025-6543 in Citrix NetScaler targeting Dutch critical organizations months before disclosure. Advanced evasion techniques allow persistent access, urging full forensic reviews. #CVE2025 #NetScaler #Netherlands https://t.co/vRtPw7WBXw
@TweetThreatNews
12 Aug 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Today's top 5 cybersecurity news - August 12, 2025 1. The Dutch National Cyber Security Centre (NCSC-NL) has confirmed active exploitation of a critical vulnerability, CVE-2025-6543, in Citrix NetScaler ADC products, targeting key organizations in the Netherlands. Source: The
@NewsNerdie
12 Aug 2025
44 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Citrix NetScaler vulnerability CVE-2025-6543 actively exploited in crucial industries https://t.co/J6CQFEfL5D
@DemolisherDigi
12 Aug 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/CHS7CE1RJp https://t.co/ls4J6v2nBL
@talentxfactor
12 Aug 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors - https://t.co/UXvyc7z577 #critical #cve-2025-6543 #confirms
@cyntelnext
12 Aug 2025
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/XBpd80wIiU
@Dinosn
12 Aug 2025
1642 Impressions
3 Retweets
9 Likes
2 Bookmarks
0 Replies
0 Quotes
📌 أكد المركز الوطني للأمن السيبراني الهولندي (NCSC-NL) وجود هجمات إلكترونية تستغل ثغرة أمنية خطيرة في منتجات Citrix NetScaler ADC، وهي CVE-2025-6543، لاستهداف مؤسسات حيوية
@Cybercachear
12 Aug 2025
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/2qiroLvz4S
@molari999
12 Aug 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The Hacker News - Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/hyzNdowyab
@buzz_sec
12 Aug 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/lNxb9YIOe5
@DemolisherDigi
12 Aug 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors https://t.co/XeQLkqrWz9 https://t.co/f159X1VAJA
@RigneySec
12 Aug 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Netherlands: Citrix NetScaler flaw CVE-2025-6543 exploited to breach orgs A critical Citrix NetScaler vulnerability-CVE-2025-6543-is being actively exploited to breach organizations in the Netherlands. Most.... @CosmicMetaX #Netz https://t.co/Kf5utz1Zhu
@CosmicMetaX
12 Aug 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs The Netherlands' National Cyber Security Centre (NCSC) is warning that a critical Citrix NetScaler v #netherlands #citrix #netscaler #flaw #cve20256543 #exploited #breach #orgs https://t.co/aMnUuR0IeA
@DConsultinguk
12 Aug 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Netherlands' NCSC warns that the critical Citrix NetScaler flaw CVE-2025-6543, a memory overflow, has been exploited as a zero-day since May 2025. Multiple vital organizations were breached, with attackers deploying stealthy web shells and erasing forensic traces. Patch
@ransomnews
12 Aug 2025
876 Impressions
4 Retweets
12 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Netherlands' NCSC warns that the critical Citrix NetScaler flaw CVE-2025-6543**,** a memory overflow, has been exploited as a zero-day since May 2025. Multiple vital organizations were breached, with attackers deploying stealthy web shells and erasing forensic traces. P
@ransomnews
12 Aug 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The NCSC alerts on exploited Citrix NetScaler vulnerability (CVE-2025-6543) affecting critical organizations, enabling remote code execution and denial of service. Citrix recommends upgrades; a GitHub script is available for scanning. #Security https://t.co/g6EYWrQq41
@Strivehawk
11 Aug 2025
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The Netherlands' NCSC is warning that a critical #Citrix NetScaler vulnerability tracked as #CVE-2025-6543 was exploited to breach "critical organizations" in the country. Initially labelled a DoS vulnerability it appears unknown threat actors have found a way to achieve #RCE.
@Gi7w0rm
11 Aug 2025
8835 Impressions
20 Retweets
67 Likes
30 Bookmarks
2 Replies
0 Quotes
Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs https://t.co/MIy9t2Ekzl #Security https://t.co/PrsXttadui
@blueteamsec1
11 Aug 2025
1381 Impressions
1 Retweet
9 Likes
2 Bookmarks
0 Replies
0 Quotes
Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs https://t.co/zn6fwQbOFc #Security
@TheCyberSecHub
11 Aug 2025
569 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs - @billtoulas https://t.co/0dvf1UZ1w7 https://t.co/0dvf1UZ1w7
@BleepinComputer
11 Aug 2025
6892 Impressions
23 Retweets
68 Likes
12 Bookmarks
0 Replies
0 Quotes
#VulnerabilityReport #ADC Urgent Citrix NetScaler Alert: Critical Memory Overflow Flaw (CVE-2025-6543, CVSS 9.2) Actively Exploited on 2,100+ Unpatched Appliances https://t.co/LKZin16p88
@Komodosec
6 Aug 2025
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Upgraded NetScaler 13.1 (b59.19) for CVE-2025-6543 & now seeing service failures? We found the culprit. Our new blog breaks down symptoms, root cause & why 4GB+ is the new baseline. Read more below: https://t.co/Nqls2iWXXL #NetScaler #Citrix #NetworkTroubleshooting htt
@FerroqueSystems
5 Aug 2025
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
#hacksnap Got an itch to hack Snapchat’s deepest corners ?🔑 #snapchatleak #hack #snaphack #snapchatsupport #hackeyesonly #snapchatrecovery #fypシ #snapchatleak #StrayKids #LoveIsland CVE-2025-6543 (CVSS 9.2) is being exploited in the wild-affecting NetScaler ADC VPN
@rayhackz
27 Jul 2025
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#hacksnap Got an itch to hack Snapchat’s deepest corners ?🔑 #snapchatleak #hack #snaphack #snapchatsupport #hackeyesonly #snapchatrecovery #fypシ #snapchatleak #StrayKids #LoveIsland CVE-2025-6543 (CVSS 9.2) is being exploited in the wild-affecting NetScaler ADC VPN
@cybersecur80472
25 Jul 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F079648-790A-4D18-908D-25CA575C5B46",
"versionEndExcluding": "13.1-37.236",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF89AD2E-8A0A-43A9-9EEB-83D595576775",
"versionEndExcluding": "13.1-37.236",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "355DCB05-54E3-4C13-A74A-B27CE3F10597",
"versionEndExcluding": "13.1-59.19",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A26624D-7F3F-4FD7-AC50-C9BDCA656F7B",
"versionEndExcluding": "14.1-47.46",
"versionStartIncluding": "14.1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "598029C6-734C-450C-A7EC-495C72819E88",
"versionEndExcluding": "13.1-59.19",
"versionStartIncluding": "13.1"
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D977C8AE-4B4E-474D-ABD6-F55F054E5B59",
"versionEndExcluding": "14.1-47.46",
"versionStartIncluding": "14.1"
}
],
"operator": "OR"
}
]
}
]