
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6543 is a memory overflow (buffer overflow) vulnerability in Citrix NetScaler ADC and NetScaler Gateway that leads to unintended control flow and can enable remote code execution or Denial of Service. It affects devices configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Affected versions include NetScaler ADC and Gateway 13.1 before 13.1-59.19 (standard), 13.1 before 13.1-37.236 (FIPS/NDcPP), and 14.1 before 14.1-47.46. The vulnerability was publicly disclosed on June 25, 2025, but evidence indicates it was exploited as a zero-day beginning in mid-May 2025 — nearly two months before the patch was released. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (Citrix Advisory, CISA KEV).
The vulnerability is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), specifically a buffer overflow in the NetScaler ADC and Gateway components when configured in Gateway or AAA virtual server mode. An unauthenticated remote attacker can send specially crafted network requests to trigger the memory overflow, leading to unintended control flow — enabling arbitrary code execution or service disruption. No authentication or user interaction is required, and the attack vector is entirely network-based. The vulnerability has been nicknamed "CitrixBleed 2" by the security community, drawing parallels to the original CitrixBleed (CVE-2023-4966). Multiple public proof-of-concept exploits have been released on GitHub, and researcher Kevin Beaumont (DoublePulsar) published analysis confirming the vulnerability was exploited as a zero-day since May 2025 (Rapid7 ETR, DoublePulsar, Wiz Blog).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected NetScaler device, modify system data, or crash the NetScaler service entirely. Because NetScaler ADC and Gateway devices serve as critical network perimeter components — handling VPN, remote access, and authentication — compromise can provide attackers with a foothold into internal enterprise networks, enabling lateral movement, credential theft, and data exfiltration. Real-world exploitation in the Netherlands resulted in breaches of multiple critical-sector organizations, including a Dutch cancer screening laboratory where data of approximately 485,000 individuals was stolen. The Dutch NCSC confirmed that multiple threat actors, including groups attributed to Russia, exploited this vulnerability against critical infrastructure (BleepingComputer, The Hacker News, BankInfoSecurity).
/vpn/index.html, /logon/LogonPoint/index.html)./vpn/, /logon/, or AAA virtual server endpoints.nsppe or related NetScaler daemons./netscaler/, /var/nslog/); new or modified files in /flash/nsconfig/ or /var/ directories; unauthorized SSH keys added to the appliance.https://github.com/NCSC-NL/citrix-2025/tree/main/live-host-bash-check (NCSC-NL GitHub, Security Affairs).Citrix released patches on June 25, 2025. Organizations should upgrade to the following fixed versions immediately:
Note: NetScaler ADC and Gateway versions 12.1 and 13.0 are end-of-life and should be migrated to a supported version. CISA mandated remediation for federal agencies by July 21, 2025. If immediate patching is not possible, consider restricting access to NetScaler management interfaces and Gateway endpoints to trusted IP ranges. Citrix also noted that some customers experienced login issues after applying the auth bypass patch; a follow-up fix was released to address this (Citrix Advisory, CISA KEV, BleepingComputer).
Citrix/NetScaler issued an emergency security advisory and blog post urging immediate patching, describing the vulnerability as critical severity (NetScaler Blog). The Dutch NCSC (NCSC-NL) issued a public advisory confirming active exploitation against critical Dutch organizations and released a detection script on GitHub. Security researcher Kevin Beaumont (DoublePulsar) published a detailed analysis revealing that Citrix failed to disclose that the vulnerability had been exploited as a zero-day since May 2025, generating significant community criticism. Rapid7, Wiz, Tenable, ReliaQuest, and Arctic Wolf all published threat intelligence reports and FAQs. The vulnerability was widely dubbed "CitrixBleed 2" by the security community. Multiple national CERTs (CERT-EU, Canadian CCCS, Australian ACSC, New Zealand CERT, Belgian CCB) issued advisories. The Register, BleepingComputer, The Hacker News, and CyberScoop provided extensive coverage, and the story trended on security-focused social media platforms (DoublePulsar, The Register, BleepingComputer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."