CyberzSOC

Publication detail
← Back to advisories & guidance

2025-022: Severe Vulnerabilities in Citrix Products ↗ source

June 26, 2025 CERT-EU Advisory

Summary

On 17 June 2025, Citrix released an advisory addressing two high severity vulnerabilities in NetScaler ADC and NetScaler Gateway [1]. [New] On June 25, Citrix released another advisory addressing one high severity vulnerability in NetScaler ADC and NetScaler Gateway [2]. Citrix warns that exploits of CVE-2025-6543 on unmitigated appliances have been observed. It is recommended updating affected assets as soon as possible. The vulnerability CVE-2025-5777, with a CVSS score of 9.3, is due to insufficient input validation leading to memory overread [1]. To be exploitable, NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. The vulnerability CVE-2025-5349, with a CVSS score of 8.7, is due to improper access control on the NetScaler Management Interface [1].

News Coverage

DateSourceArticle
2026-07-02 The Hacker News Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials CVE-2025-5777

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-5777 9.3 Critical Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to mem…
CVE-2025-6543 9.2 Critical Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be …
CVE-2025-5349 8.7 High NetScaler ADC Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.