Citrix disclosed CVE-2025-6543, a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that affects devices configured as a Gateway or AAA virtual server. The flaw can trigger unintended control-flow redirection and service disruption, leading to denial of service, and was assigned a CVSS v4.0 score of 9.2. Affected releases include NetScaler ADC and Gateway 14.1 before 14.1-47.46, 13.1 before 13.1-59.19, and NetScaler ADC 13.1-FIPS/NDcPP before 13.1-37.236-FIPS/NDcPP; Citrix also said Secure Private Access on-prem and hybrid deployments using NetScaler instances are impacted.
Citrix directed customers to upgrade immediately to fixed builds or discontinue use where no supported update is available, with the issue tracked in Citrix advisory CTX694826 and the CVE record CVE-2025-6543. Follow-on guidance warned that upgrading to 14.1-47.46 or 13.1-59.19 may introduce authentication problems, including broken login pages in environments using DUO or SAML, and the company published remediation steps for affected deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Citrix later reported that upgrading to versions 14.1-47.46 or 13.1-59.19 could introduce authentication problems, including broken login pages, particularly in environments using DUO or SAML. The company provided remediation guidance for affected deployments.
Citrix recommended immediate upgrades to fixed versions, including 14.1-47.46, 13.1-59.19, and 13.1-37.236-FIPS/NDcPP for affected NetScaler deployments. It also advised discontinuing use where no update was available.
Citrix disclosed CVE-2025-6543, a critical memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway when configured as a Gateway or AAA virtual server. The flaw can cause unintended control-flow redirection and service disruption leading to denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.