Citrix Security Update – 29 June 2025

Citrix has released a security update to address a vulnerability affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.

The addressed vulnerability could allow the remote attacker to cause a memory overflow, leading to unintended control flow and a denial of service attack.

Improper Restriction of Operations Within The Bounds of a Memory Buffer Vulnerability (CVE-2025-6543):

  • CVSS: 9.2
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

It should be highlighted that security researchers have discovered that the vulnerability “CVE-2025-5777”, which was addressed by Citrix on June 17, 2025, is now likely being exploited in the wild.

Vulnerabilities

CVE-2025-6543

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Citrix Security Update

References