CVE-2025-6543 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 10.6% (pctl 96)
Patch first
On CISA KEV — known exploited in the wild, due 2025-07-21.
Description
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 10.56% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | yes — remediate by 2025-07-21 |
| Public exploit | none known |
| Published | 2025-06-25 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability |
|---|---|
| Added | 2025-06-30 |
| Due | 2025-07-21 |
| Vendor / product | Citrix / NetScaler ADC and Gateway |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| citrix | netscaler application delivery controller |
| citrix | netscaler gateway |
References
→ the Explorer · watch your stack · NVD