← Vulnerability feed

Vulnerability record · CVE-2025-6543 · published 25 June 2025

CVE-2025-6543: Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoS

Citrix · Netscaler Application Delivery Controller

NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, so internet-facing remote access deployments are the exposed ones. The flaw is remotely reachable without authentication, and CISA added it to the Known Exploited Vulnerabilities catalog, making it a priority for edge-device patching.

9.2 CVSS 4.0 Critical CISA KEV since 30 Jun 2025 EPSS 11% · top 4.4% CWE-119 · Memory buffer overflow
9.2CVSS 4.0 base score
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityRemote unauthenticated memory corruption in internet-facing Citrix remote access appliances that is listed in CISA KEV with confirmed exploitation.

What it is

NetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, so internet-facing remote access deployments are the exposed ones. The flaw is remotely reachable without authentication, and CISA added it to the Known Exploited Vulnerabilities catalog, making it a priority for edge-device patching.

Impact

An unauthenticated remote attacker can corrupt memory to redirect control flow and crash the appliance, disrupting VPN, ICA, RDP and AAA services. The CVSS 4.0 vector rates high confidentiality, integrity and availability impact, so code execution or data exposure beyond the DoS cannot be ruled out from the record.

Attack surface

Reached over the network via the Gateway or AAA virtual server on NetScaler ADC or Gateway; the CVSS vector shows no privileges required and no user interaction. Only appliances configured in those roles are affected, so exposure depends on the deployed configuration.

Exploitation

CVE-2025-6543 is listed in CISA KEV with a 2025-07-21 remediation due date, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 10.1 percent (95th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor fix from Citrix advisory CTX694788 to all NetScaler ADC and Gateway appliances, prioritizing Gateway and AAA virtual server configurations.
  • If patching cannot be done immediately, follow Citrix mitigation guidance or take the affected Gateway/AAA virtual server out of service per CISA BOD 22-01.
  • Restrict management and virtual server access to trusted networks and disable unused Gateway or AAA virtual servers.
  • Monitor Citrix and CISA advisories for updated guidance and verify patch level after upgrading.

Detection

  • Review NetScaler logs for unexpected appliance restarts, crashes or process failures on Gateway and AAA virtual servers.
  • Alert on anomalous or malformed traffic to VPN, ICA Proxy, CVPN, RDP Proxy and AAA virtual server endpoints.
  • Audit NetScaler build versions against the fixed release in CTX694788 and flag unpatched appliances.
  • Correlate NetScaler availability gaps with upstream network telemetry to catch denial-of-service attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-6543 to the Known Exploited Vulnerabilities catalog on 30 June 2025 as "Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 21 July 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-6543 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2025-6543), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.