Citrix bleeds again: This time a zero-day exploited - patch now
ID: 6586162d-1b8c-5836-a75a-90718779f479
STIX ID: report--6586162d-1b8c-5836-a75a-90718779f479
Feed Name: The Register (Security)
Citrix issued emergency patches for a critical memory-overflow vulnerability (CVE-2025-6543, CVSS 9.2) in NetScaler ADC/Gateway that has been observed exploited as a zero-day; affected NetScaler 14.1, 13.1 and some EOL versions may allow unintended control flow, DoS or code execution. The report also references a previously disclosed critical issue (CVE-2025-5777) affecting the same products and emphasizes immediate patching and session termination because intrusions may already have resulted in backdoors or stolen session secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
