CVE-2025-6543Active Exploitation(citrix / netscaler_application_delivery_controller)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-21. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Peaked at 2 mentions on most recent observed day (2026-10-05)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-26: 1Mentions · 2026-10-05: 2Active Exploitation · 2026-05-26: 1Technical Details · 2026-05-26: 105-2610-05
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Sagar Tanur 🇮🇳@Sagarvd01

    @TheHackersNews quick check if you run NetScaler: grep the config for samlAction or samlIdPProfile, that's the precondition. also wouldn't lean too hard on "DoS only" for a memory overflow. CVE-2025-6543 carried the same label in 2025 and webshells showed up later

    00010147
    195 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Dutch NCSC warns CVE-2025-6543 Citrix bug, a memory overflow flaw, is being exploited to breach critical organizations in the Netherlands. The Dutch NCSC warns that the critical Citrix NetScaler flaw CVE-2025-6543 has b... https://f.mtr.cool/zdavkmwder

    Post summary

    Dutch NCSC warns that CVE‑2025‑6543, a memory overflow flaw in Citrix NetScaler, is currently being exploited against critical organizations in the Netherlands, with no known patches or PoC disclosed.

    00010205
    2.1K followersView on X
  • skinnyguinea@_skinnyguinea

    Another NetScaler zero-day. CVE-2026-88779 hits ADC/Gateway boxes using SAML auth. Citrix calls it DoS, but researchers are seeing signs it can reach RCE, same pattern as CVE-2025-6543. CISA KEV deadline is Oct 7. Patch to 14.1-73.41 / 13.1-64.28 tonight, not Monday. https://www.bleepingcomputer.com/news/security/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/

    0000085
    110 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more