CVE-2025-6543CRITICAL 9.8CISA KEVEPSS p94.9%
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Citrix / NetScaler ADC and Gateway
Description
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.76% probability of exploitation · percentile 94.9% · 2026-06-19T12:03:05Z |
| Published | 2025-06-25 |
| Last modified | 2025-10-24 |
CISA KEV entry
Added to KEV: 2025-06-30
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerabilitykev-cve-2025-6543 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.