>> All posts

CVE-2025-6543: Citrix NetScaler memory overflow, unauthenticated and exploited in the wild

The short version: CVE-2025-6543 is a memory-overflow flaw in NetScaler ADC and Gateway that leads to unintended control flow and denial of service when the appliance is configured as a Gateway or AAA virtual server. It's unauthenticated, it was exploited as a zero-day, and it's in CISA's KEV catalog. NVD scores it 9.8. Patch and confirm — this is one more in NetScaler's long run of edge-appliance bugs. Steady hands, but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated, exploited, on a perimeter appliance
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS (Citrix, CNA)9.2 — Critical · CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
EPSS~9.8% · 95.0th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-07-21
Known exploited?Yes — exploited as a zero-day before broad patching
Vulnerability typeCWE-119 memory buffer overflow → unintended control flow / denial of service
Requires authenticated session?No — pre-authentication (device must be configured as a Gateway or AAA virtual server)
AffectedNetScaler ADC & Gateway configured as a Gateway/AAA vServer: 13.1 and 14.1 trains prior to the fixed builds, plus 13.1-FIPS/NDcPP (12.1 and 13.0 are EOL and not evaluated)
Fixed in14.1-47.46 · 13.1-59.19 · 13.1-37.236 (FIPS/NDcPP) and later — confirm against CTX694788

What you need to know

NetScaler ADC/Gateway is Citrix's edge access appliance. CVE-2025-6543 is a memory overflow that an unauthenticated attacker can trigger when the device is configured as a Gateway (VPN vServer, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, causing unintended control flow and denial of service.

Why it ranks at the top:

  • It's the access appliance, unauthenticated. No credential, and it targets the box that fronts your remote access.
  • It was live before the fix. Citrix and CISA documented exploitation before broad patching — an affected appliance may have been probed pre-patch.
  • The impact framing is broad. Citrix describes control-flow disruption and DoS; NVD scores full confidentiality/integrity/availability impact (9.8), reflecting how dangerous memory-corruption on a perimeter device can be.

How serious we see it

High — both NVD (9.8) and Citrix (9.2) land in the Critical band, it's unauthenticated, it's KEV-listed, and it was exploited as a zero-day. Memory-corruption on an internet-facing access appliance, being actively used, is top-of-queue regardless of whether the demonstrated outcome is disruption or something deeper. The bounded, reassuring part: it affects specific 13.1/14.1 builds in the Gateway/AAA configuration, the fixes are published, and the vulnerable configuration is easy to confirm. As with every pre-patch zero-day, being patched and being clean are separate questions.

Recommendations

Straight from Citrix's bulletin (CTX694788) and CISA:

  1. Patch now. Upgrade to 14.1-47.46 / 13.1-59.19 (or the matching FIPS/NDcPP build 13.1-37.236) or later. NetScaler 12.1 and 13.0 are End-of-Life — migrate off them.
  2. Hunt. Follow Citrix's guidance to check for signs of exploitation and instability; a pre-patch window means patched isn't automatically clean.
  3. Terminate sessions where advised. Follow Citrix's post-upgrade session-handling guidance to clear any state an attacker may have established.
  4. Harden exposure. Keep management interfaces private; limit internet reachability to what the Gateway needs.
  5. Confirm your exposure first. Verify your build and whether it's configured as a Gateway/AAA vServer.

How BreachRisk sees it

BreachRisk starts from the outside, the way an attacker does. From little more than your domain it discovers internet-facing NetScaler Gateway interfaces, fingerprints the build, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — pushed to the top of your results because it's in KEV.

NetScaler has been targeted again and again; the value of a continuous, outside-in view is that each new edge-appliance bug lands against an asset map you already have, so you go straight to patch-and-verify.

References

See your cyber risk, proven.