EXPOSURES › CVE-2025-6543
CVE-2025-6543
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix NetScaler ADC and Gateway suffered a buffer overflow that led to unintended control flow and Denial of Service, actively exploited in the wild.
Citrix NetScaler products, used widely in DIB, have a critical buffer overflow vulnerability that has been actively exploited, causing service disruptions. Configured as gateways, these devices are at risk of remote code execution and Denial of Service attacks.
Shame score — Active exploitation in the wild indicates negligence in maintaining security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |