• News/
  • https://www.bleepingcomputer.com/news/security/citrix-warns-of-netscaler-vulnerability-exploited-in-dos-attacks/

Citrix warns of NetScaler vulnerability exploited in DoS attacks

BleepingComputer
·
Lawrence Abrams
·
Published Jun 25, 2025
·
Updated

Citrix is warning that a vulnerability in NetScaler appliances tracked as CVE-2025-6543 is being actively exploited in the wild, causing devices to enter a denial of service condition. "Exploits of CVE-2025-6543 on unmitigated appliances have been observed," warns Citrix's advisory. Tracked internally as CTX694788, CVE-2025-6543 is a critical flaw impacting NetScaler ADC and NetScaler Gateway and can be triggered by unauthenticated, remote requests, leading the appliance to go offline. The flaw impacts NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-47.46, 13.1 before 13.1-59.19, and NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.236-FIPS and NDcPP. It only affects NetScaler devices configured as a Gateway (VPN virtual server, ICA Proxy, Clientless VPN (CVPN), RDP Proxy) or an AAA virtual server. Citrix fixed the flaw in NetScaler ADC and Gateway 14.1-47.46, 13.1-59.19, and ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.236 and later releases of 13.1-FIPS and 13.1-NDcPP. The warning arrives as admins deal with another critical NetScaler flaw dubbed CitrixBleed 2. That bug, tracked as CVE-2025-5777, allows attackers to hijack user sessions by extracting session tokens from a device's memory. A similar Citrix flaw named "CitrixBleed" was previously used by ransomware gangs and in attacks on governments in 2023 to gain widescale access to NetScaler devices and move laterally across corporate environments. With both flaws being critical bugs, administrators are advised to ...

Read full article

Affected Software

6 affected components
Citrix NetScaler ADC=14.1 before 14.1-47.46
Citrix NetScaler Gateway=14.1 before 14.1-47.46
Citrix NetScaler ADC=13.1 before 13.1-59.19
Citrix NetScaler ADC=13.1-FIPS before 13.1-37.236-FIPS
Citrix NetScaler ADC=NDcPP before 13.1-37.236-FIPS
Citrix NetScaler Gateway=13.1 before 13.1-59.19
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in Citrix NetScaler appliances that is being exploited in denial of service (DoS) attacks.

2

What security implications are discussed in the article?

The article warns that unmitigated appliances are at risk of being exploited, leading to DoS conditions.

3

What specific vulnerability is identified in the Citrix advisory?

The vulnerability identified is tracked as CVE-2025-6543.

4

Which Citrix products are affected by this vulnerability?

The affected products include Citrix NetScaler ADC and Citrix NetScaler Gateway.

5

What action does Citrix recommend regarding the vulnerability?

Citrix advises users to implement mitigations to protect their appliances from the exploitation of this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Citrix warns of NetScaler vulnerability exploited in DoS attacks - SecAlerts