logo

Citrix warns of exploitation of Netscaler devices through new bugs

ID: 16d1e443-b60e-5a4f-b552-74c0403dc941

STIX ID: report--16d1e443-b60e-5a4f-b552-74c0403dc941

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-06-25

Date Updated: 2026-05-01

...
...

Citrix published an advisory for CVE-2025-6543 (CVSS 9.2) affecting NetScaler ADC and Gateway appliances and reported that exploitation has been observed on unmitigated devices; two related bugs (CVE-2025-5349 and CVE-2025-5777) could expose session tokens and enable MFA bypass. Researchers and authorities compared these flaws to the 2023 'Citrix Bleed' vulnerabilities that were widely exploited by ransomware groups, warning that thousands of NetScaler installations connected to the internet are at risk and urging prompt software updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.