Don't Just Read the News, Understand It.
Published loading...Updated

Citrix warns of NetScaler vulnerability exploited in DoS attacks

  • On Wednesday, Citrix revealed a zero-day vulnerability that is currently being exploited and affects several versions of its NetScaler ADC and Gateway products.
  • This vulnerability follows recent advisories for CVE-2025-5777 and CVE-2025-5349, and relates to previous CitrixBleed flaws exploited widely in 2023 by nation-state and criminal actors.
  • CVE-2025-6543, a memory overflow defect with a CVSS score of 9.2, allows remote unauthenticated attackers to cause denial of service and control flow issues on unpatched NetScaler devices configured as gateways.
  • Citrix urged immediate patching, and security experts like Ben Harris cautioned it is more dangerous than initially described, while noting denial-of-service states may indicate failed exploits, not the intended outcome.
  • The situation implies ongoing risks for critical infrastructure, prompting agencies and Cloud Software Group to strongly recommend upgrading and monitoring NetScaler appliances to prevent widespread compromise.
Insights by Ground AI
Does this summary seem wrong?

11 Articles

All
Left
Center
3
Right
Global Security Mag OnlineGlobal Security Mag Online
Reposted by
Global Security Mag OnlineGlobal Security Mag Online

Multiple vulnerabilities have been discovered in Citrix products. Some of them allow an attacker to cause arbitrary remote code execution, a denial of service at a distance and a breach of data confidentiality. Citrix indicates that the vulnerability... See online: https://www.cert.ssi.gouv.fr/avis/C...

Read Full Article

In Citrix Netscaler instances, several security corners are opened. One reminds of Citrix Bleed, another is already being exploited. (Security corner, server)

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Cybersecurity Dive broke the news in on Wednesday, June 25, 2025.
Sources are mostly out of (0)

Similar News Topics

You have read 1 out of your 5 free daily articles.

Join millions of well-informed readers who use Ground to compare coverage, check their news blindspots, and challenge their worldview.