CVE detail
CVE-2025-6543 — Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Published 2025-06-30 · Modified 2025-06-30 · Source kev
HIGH
severity
CVSS-derived band
0.1009
EPSS probability
exploitation probability, 30d
95.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2025-07-21
⚠ Actively exploited in the wild — CISA KEV listed 2025-06-30, federal remediation due 2025-07-21.
Description
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References