logo

Citrix bleeds again: This time a zero-day exploited - patch now

ID: 6586162d-1b8c-5836-a75a-90718779f479

STIX ID: report--6586162d-1b8c-5836-a75a-90718779f479

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-06-25

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Citrix issued emergency patches for a critical memory-overflow vulnerability (CVE-2025-6543, CVSS 9.2) in NetScaler ADC/Gateway that has been observed exploited as a zero-day; affected NetScaler 14.1, 13.1 and some EOL versions may allow unintended control flow, DoS or code execution. The report also references a previously disclosed critical issue (CVE-2025-5777) affecting the same products and emphasizes immediate patching and session termination because intrusions may already have resulted in backdoors or stolen session secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.