peter bassill · operator
$ cve CVE-2025-6543 JSON

CVE-2025-6543 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 10.6% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2025-07-21.

Description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.56% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2025-07-21
Public exploitnone known
Published2025-06-25
Last modified2026-06-17

CISA KEV

NameCitrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Added2025-06-30
Due2025-07-21
Vendor / productCitrix / NetScaler ADC and Gateway
Ransomware usenone reported

Affected (2)

VendorProduct
citrixnetscaler application delivery controller
citrixnetscaler gateway

References

→ the Explorer  ·  watch your stack  ·  NVD