• News/
  • https://www.theregister.com/2025/06/25/citrix_netscaler_critical_bug_exploited/

Citrix bleeds again: This time a zero-day exploited - patch now

The Register
·
Jessica Lyons
·
Published Jun 25, 2025
·
Updated

Hot on the heels of patching a critical bug in Citrix-owned Netscaler ADC and NetScaler Gateway that one security researcher dubbed "CitrixBleed 2," the embattled networking device vendor today issued an emergency patch for yet another super-serious flaw in the same products — but not before criminals found and exploited it as a zero-day. This new critical vulnerability, tracked as CVE-2025-6543, received a 9.2 severity score. It's a memory overflow vulnerability that can lead to unintended control flow and denial of service when the affected security appliances are configured as a gateway virtual server or an authentication, authorization, and accounting (AAA) virtual server. It affects: And, according to the vendor, miscreants exploited CVE-2025-6543 as a zero-day vulnerability before Citrix fixed the flaw. "Exploits of CVE-2025-6543 on unmitigated appliances have been observed," according to a security bulletin. Citrix did not respond to The Register's inquiries about the flaw, including how many devices have been compromised and what the intruders have done with their illicit access. According to watchTowr CEO Benjamin Harris, however, the 9.2 critical CVSS rating and the fact that it was exploited as a zero-day indicate that the miscreants abusing this hole are doing more than just denial-of-service (DoS) attacks. "The CVSS metrics reflect code execution or similar, not DoS as the most impactful outcome," Harris told The Register. "Vulnerable appliances being observed to...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability found in Citrix's NetScaler ADC and NetScaler Gateway that is being actively exploited.

2

What security implications are discussed in the article?

The article highlights the significant risk posed by the zero-day exploit, urging users to apply an emergency patch to protect their systems.

3

What products or software are affected by the vulnerability?

The affected products include Citrix NetScaler ADC and Citrix NetScaler Gateway.

4

What is the urgency mentioned regarding the patch?

The article emphasizes the urgency of applying the patch due to the ongoing exploitation of the zero-day flaw.

5

Who identified the new vulnerability referred to as 'CitrixBleed 2'?

The new vulnerability was identified by a security researcher, who labeled it 'CitrixBleed 2'.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203