Hot on the heels of patching a critical bug in Citrix-owned Netscaler ADC and NetScaler Gateway that one security researcher dubbed "CitrixBleed 2," the embattled networking device vendor today issued an emergency patch for yet another super-serious flaw in the same products — but not before criminals found and exploited it as a zero-day. This new critical vulnerability, tracked as CVE-2025-6543, received a 9.2 severity score. It's a memory overflow vulnerability that can lead to unintended control flow and denial of service when the affected security appliances are configured as a gateway virtual server or an authentication, authorization, and accounting (AAA) virtual server. It affects: And, according to the vendor, miscreants exploited CVE-2025-6543 as a zero-day vulnerability before Citrix fixed the flaw. "Exploits of CVE-2025-6543 on unmitigated appliances have been observed," according to a security bulletin. Citrix did not respond to The Register's inquiries about the flaw, including how many devices have been compromised and what the intruders have done with their illicit access. According to watchTowr CEO Benjamin Harris, however, the 9.2 critical CVSS rating and the fact that it was exploited as a zero-day indicate that the miscreants abusing this hole are doing more than just denial-of-service (DoS) attacks. "The CVSS metrics reflect code execution or similar, not DoS as the most impactful outcome," Harris told The Register. "Vulnerable appliances being observed to...
Citrix bleeds again: This time a zero-day exploited - patch now
The Register
·Jessica Lyons
·Published Jun 25, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical zero-day vulnerability found in Citrix's NetScaler ADC and NetScaler Gateway that is being actively exploited.
2
What security implications are discussed in the article?
The article highlights the significant risk posed by the zero-day exploit, urging users to apply an emergency patch to protect their systems.
3
What products or software are affected by the vulnerability?
The affected products include Citrix NetScaler ADC and Citrix NetScaler Gateway.
4
What is the urgency mentioned regarding the patch?
The article emphasizes the urgency of applying the patch due to the ongoing exploitation of the zero-day flaw.
5
Who identified the new vulnerability referred to as 'CitrixBleed 2'?
The new vulnerability was identified by a security researcher, who labeled it 'CitrixBleed 2'.