Vulnerability Intelligence Report
Memory overflow vulnerability leading to unintended control flow and Denial of Service
CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
9.2
CRITICAL
EPSS Probability:9.76%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-119 ↗CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| NetScaler | ADC | 14.1 < 47.46 (affected), 13.1 < 59.19 (affected), 13.1 FIPS and NDcPP < 37.236 (affected) |
| NetScaler | Gateway | 14.1 < 47.46 (affected), 13.1 < 59.19 (affected), 13.1 FIPS and NDcPP < 37.236 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Citrix Systems, Inc. · Vendor · USA |
| Reserved | 2025-06-23T18:08:23 |
| Published | 2025-06-25T12:49:57 |
| Patch Date | 2025-06-25 |
| Last Updated | 2026-02-26T17:50:24 |
Community Chatter & Buzz