Critical memory overflow vulnerability in NetScaler ADC and Gateway that allows remote network exploitation leading to denial of service and potential code execution. The vulnerability is actively exploited in the wild as a zero-day since May 2025.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-06-25
Added to CISA KEV: 2025-06-30 5 DAYS BETWEEN CVE AND KEV
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway.
CVE-2025-6543 - Memory overflow vulnerability leading to unintended control flow and Denial of Service. Sign in.Netscaler Application Delivery Controller.
CVE-2025–6543 is a vulnerability which allows an attacker to supply a client certificate, which overwrites memory. This then allows code ...
Zero day exploitation in the wild of NetScaler ADC and NetScaler Gateway has been disclosed, due to a new vulnerability CVE-2025-6543.
Dutch NCSC warns of CVE-2025-6543 Citrix attacks on critical organizations, urging urgent patches to prevent further breaches.