• News/
  • https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/

Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs

BleepingComputer
·
Bill Toulas
·
Published Aug 11, 2025
·
Updated

The Netherlands' National Cyber Security Centre (NCSC) is warning that a critical Citrix NetScaler vulnerability tracked as CVE-2025-6543 was exploited to breach "critical organizations" in the country. The critical flaw is a memory overflow bug that allows unintended control flow or a denial of service state on impacted devices. "Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server," explains Citrix's advisory. Citrix issued a bulletin about the flaw on June 25, 2025, warning that the following versions were vulnerable to ongoing attacks: While the flaw was initially thought to be exploited in denial of service (DoS) attacks, the NCSC's warning now indicates that the attackers exploited it to achieve remote code execution. The NCSC's warning about CVE-2025-6543 confirms that hackers have leveraged the flaw to breach multiple entities in the country, and then wiped traces of the attacks to eliminate evidence of the intrusions. "The NCSC has determined that multiple critical organizations in the Netherlands have been successfully attacked via a vulnerability identified as CVE-2025-6543 in Citrix NetScaler," reads the notice. "The NCSC assesses the attacks as the work of one or more actors with an advanced modus operandi. The vulnerability was exploited as a zero-day, and traces were actively removed to conce...

Read full article

Affected Software

2 affected components
Citrix NetScaler=ADC
Citrix NetScaler=Gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article highlights the exploitation of a critical vulnerability in Citrix NetScaler, tracked as CVE-2025-6543, which has led to breaches of important organizations in the Netherlands.

2

What security implications are discussed in the article?

The article discusses how the CVE-2025-6543 vulnerability poses significant risks to critical organizations by allowing attackers to exploit the flaw for unauthorized access.

3

What products or software are affected by the vulnerability?

The affected products include Citrix NetScaler ADC and Citrix NetScaler Gateway.

4

Who issued the warning about the vulnerability's exploitation?

The warning was issued by the Netherlands' National Cyber Security Centre (NCSC).

5

What actions should organizations take in response to this vulnerability?

Organizations should urgently apply security patches for Citrix NetScaler and evaluate their networks for potential unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203