2025-06-25
Citrix Patches Another Critical NetScaler Flaw
On Wednesday, June 25, 2025, Citrix released a fix for a critical memory overflow vulnerability in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway. The vulnerability could lead "to unintended control flow and Denial of Service." This issue is being actively exploited in the wild and is separate from the two NetScaler vulnerabilities Citrix disclosed on June 17. Users are urged to update to the most recent versions of the affected products as soon as possible.
Editor's Note
There are two distinct vulnerabilities Citrix patched in NetScaler. The more severe one allows for memory leaks to disclose session IDs and other secrets to attackers. It is similar to the earlier, already exploited, “Citrix Leak” vulnerability. Expect an exploit to be released soon. The other vulnerability, which is already exploited, appears to only allow for a denial of service attack, but I would not trust Citrix’s analysis enough to not prioritize patching of this vulnerability.

Johannes Ullrich
The new zero-day, CVE-2025-6543, has a CVSS score of 9.2, and with the other two flaws from a week ago, you can bank on threat actors smelling blood in the water. Don’t panic, keep your NetScaler devices updated judiciously and have your threat hunters go to town on the IOCs.

Lee Neely
The Citrix bug is nasty; it's dubbed CitrixBleed 2. It's another unauthenticated out-of-bounds read on a forward-facing web interface. If you must choose which one to patch this month, this is the one.

Moses Frost
Read more in
Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543
The Record: Citrix warns of exploitation of Netscaler devices through new bugs
BleepingComputer: Citrix warns of NetScaler vulnerability exploited in DoS attacks
Cyberscoop: Citrix users hit by actively exploited zero-day vulnerability