Citrix warns of NetScaler vulnerability exploited in DoS attacks
- On Wednesday, Citrix revealed a zero-day vulnerability that is currently being exploited and affects several versions of its NetScaler ADC and Gateway products.
- This vulnerability follows recent advisories for CVE-2025-5777 and CVE-2025-5349, and relates to previous CitrixBleed flaws exploited widely in 2023 by nation-state and criminal actors.
- CVE-2025-6543, a memory overflow defect with a CVSS score of 9.2, allows remote unauthenticated attackers to cause denial of service and control flow issues on unpatched NetScaler devices configured as gateways.
- Citrix urged immediate patching, and security experts like Ben Harris cautioned it is more dangerous than initially described, while noting denial-of-service states may indicate failed exploits, not the intended outcome.
- The situation implies ongoing risks for critical infrastructure, prompting agencies and Cloud Software Group to strongly recommend upgrading and monitoring NetScaler appliances to prevent widespread compromise.
11 Articles
11 Articles
Citrix users hit by actively exploited zero-day vulnerability
Citrix on Wednesday disclosed an actively exploited zero-day vulnerability affecting multiple versions of NetScaler products, an alarming development from a vendor that’s been widely targeted in previous attack sprees. The zero-day (CVE-2025-6543) was disclosed by Citrix nine days after it issued a security bulletin for a pair of defects (CVE-2025-5777 and CVE-2025-5349) in the same products. All three vulnerabilities affect the company’s networ…


Multiple vulnerabilities have been discovered in Citrix products. Some of them allow an attacker to cause arbitrary remote code execution, a denial of service at a distance and a breach of data confidentiality. Citrix indicates that the vulnerability... See online: https://www.cert.ssi.gouv.fr/avis/C...
In Citrix Netscaler instances, several security corners are opened. One reminds of Citrix Bleed, another is already being exploited. (Security corner, server)
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium