Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-5777 | Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned. Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw. | 9.3 | 100% | KEV ransomware |
| massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of… | |
| CVE-2025-6543 | Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known. Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading. | 9.2 | 10% | KEV |
| large≈50,000+ internet-exposed NetScaler ADC/Gateway devices (only Gateway/AAA configurations vulnerable) |
Full article523 words · extracted from helpnetsecurity.com · click to collapse
FortiGuard Labs has reported a dramatic spike in exploitation attempts targeting CitrixBleed 2, a critical buffer over‑read flaw (CVE‑2025‑5777) affecting Citrix NetScaler ADC (Application Delivery Controller) and Gateway devices.

Since July 28, 2025, they have detected over 6,000 exploitation attempts, mostly in the US, Australia, Germany and the UK, “with adversaries primarily focusing on high-value sectors such as technology, banking, healthcare, and education.”
Meanwhile, the Dutch National Cyber Security Centre (NCSC‑NL) has confirmed that another NetScaler ADC vulnerability (CVE‑2025‑6543) – patched and disclosed by Citrix in late June 2025 – has been exploited as a zero-day vulnerability since early May 2025 in sophisticated, targeted attacks against critical Dutch organizations.
Active CVE‑2025‑6543 and CVE‑2025‑5777 exploitation
When Citrix released patches for CVE‑2025‑6543 on June 25, it immediately confirmed that “exploits of CVE-2025-6543 on unmitigated appliances have been observed,” but did not explain what the attackers have been using it for.
The description of the flaw says its a memory overflow vulnerability that can lead to “unintended control flow and Denial of Service” in NetScaler ADC and NetScaler Gateway when configured as Gateway or AAA virtual server.
NCSC‑NL’s latest update on the attacks says that they were sophisticated and that the attackers worked on erasing traces to conceal the compromise and make forensic investigation challenging.
“Citrix has released updates to address the vulnerability. Updating systems is not sufficient to eliminate the risk of exploitation,” the NCSC-NL pointed out. Resetting established sessions is also required.
“The NCSC is actively investigating vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, Several investigations are currently underway into the scope, nature, and impact of the attacks. Together with affected organizations, incident response organizations, and security partners, we are continuing to uncover new indicators, which we use to help other organizations in the Netherlands conduct their own investigations,” the NCSC‑NL said.
The organizations is working on updating a script that organizations can use to check their systems for the presence of indicators of compromise, and has advised organizations that discover them to contact their national cyber security incident response entity (CSIRT) for further assistance with the investigation and the clean-up.
NCSC-NL did not identify any of the affected entities, but we know about one: the country’s Public Prosecution Service confirmed it had been recently breached through Citrix systems, though they did not specify whether CVE‑2025‑5777 or CVE‑2025‑6543 had been used.
The Shadowserver Foundation says that the are seeing exploitation attempts related to both vulnerabilities in their sensors, and that there are still several thousand unpatched Citrix NetScaler devices likely vulnerable to CVE-2025-5777 and CVE-2025-6543 out there.
UPDATE (August 29, 2025, 05:20 a.m. ET):
The Dutch NCSC has released two check scripts that organizations can use to perform their own investigations into potential compromises of their systems.
“One check script focuses on coredumps, while the other check script focuses on complete NetScaler images. Instructions for running the scripts can be found in the readme files available on GitHub,” they explained.
Security researcher Kevin Beaumont has also shared threat hunting advice.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/12/citrix-netscaler-exploitation-zero-day-cve-2025-6543/