Warning: Three critical vulnerabilities (CVE-2025-5777, CVE-2025-5349, CVE-2025-6543) impact NetScaler ADC & Gateway, leading to unauthenticated memory overread, unintended control flow and Denial of Service. There is evidence of active exploitation. Pat
ID: e063836a-77bc-5d1a-bf86-be2fe66ade31
STIX ID: report--e063836a-77bc-5d1a-bf86-be2fe66ade31
**Executive summary:** Citrix NetScaler ADC and Gateway (multiple 12.x–14.x builds) are impacted by three high-severity vulnerabilities (CVE-2025-5777, CVE-2025-6543, CVE-2025-5349) that can enable session hijacking and MFA bypass, denial-of-service, and unauthorized management access; multiple vendors and researchers (Citrix, ReliaQuest, NCSC-NL) report active exploitation and the issues are listed in CISA KEV, so immediate patching, session termination, threat-hunting, and increased monitoring are strongly recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
