The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Citrix NetScaler vulnerability CVE-2025-6543 to its Known Exploited Vulnerabilities catalog.
CVE-2025-6543 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway, potentially leading to Denial of Service.
Affected versions include NetScaler ADC 13.1-FIPS, 14.1, and earlier versions, requiring prompt mitigation to protect against attacks exploiting the flaw.
CISA has issued directives for federal agencies to address the vulnerabilities by July 21, 2025, following a similar inclusion of other Citrix vulnerabilities in the past.