Friday, September 11, 2026

CISA Issues Alert on Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert following the addition of a critical Citrix NetScaler vulnerability—CVE-2025-6543—to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild.

Vulnerability Details

CVE-2025-6543 is a buffer overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an Authentication, Authorization, and Auditing (AAA) virtual server.

CVE IDVulnerability TypeImpact
CVE-2025-6543Buffer Overflow (CWE-119)DoS, Unintended Control Flow

The flaw, classified under CWE-119, allows attackers to trigger unintended control flow, potentially resulting in a Denial of Service (DoS) and service disruption.

The vulnerability has been assigned a CVSS score of 9.2 (Critical), underscoring its potential impact on confidentiality, integrity, and availability. Notably, exploitation does not require user interaction or elevated privileges, making it a prime target for remote attackers.

CISA and multiple security advisories confirm that CVE-2025-6543 is being actively exploited. Attackers have leveraged this vulnerability as a zero-day, with exploitation observed before Citrix’s public disclosure and patch release. 

While there is no public exploit code available, the risk of further attacks remains high, especially for unpatched systems.

Affected product versions include:

  • NetScaler ADC and Gateway versions before 14.1 to 43.56
  • Versions before 13.1 to 58.32
  • 13.1-FIPS and 13.1-NDcPP before 13.1 to 37.235
  • 12.1-FIPS before 12.1 to 55.328

CISA’s Binding Operational Directive (BOD) 22-01 mandates that all Federal Civilian Executive Branch (FCEB) agencies remediate the vulnerability by July 21, 2025.

Agencies are instructed to apply vendor-provided mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. 

CISA strongly urges all organizations, public and private, to prioritize patching and remediation to reduce exposure to cyberattacks.

Citrix has released security updates and advises all customers to immediately update to the latest versions to protect against ongoing attacks. The company reiterates its commitment to security-by-design and responsible disclosure practices.

Organizations are urged to act swiftly to secure their Citrix NetScaler deployments and prevent potential service outages or further exploitation.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News