← Back to browse · API

CVE-2025-6543

Severity
CRITICAL
CVSS
9.2
EPSS
0.10094
Risk score
65.33
CISA KEV
Yes
PoC
No
Published
2025-06-25
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-19085, GHSA-9GQR-6728-FPV3
Products
Citrix:NetScaler ADC and Gateway, NetScaler:ADC 13.1 <59.19, NetScaler:ADC 13.1 FIPS and NDcPP <37.236, NetScaler:ADC 14.1 <47.46, NetScaler:Gateway 13.1 <59.19, NetScaler:Gateway 13.1 FIPS and NDcPP <37.236, NetScaler:Gateway 14.1 <47.46
Sources
euvd EUVD-2025-19085
cisa.gov CVE-2025-6543

Description

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

References