About:
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
CVSS Score: 9.2 (Critical)
Identifier: CVE-2025-6543
Exploit or POC: Yes – Actively exploited in the wild via unauthenticated remote requests
Update: CVE-2025-6543 – Citrix Security Advisory
Description: CVE-2025-6543 is a critical memory overflow vulnerability in Citrix NetScaler ADC and Gateway appliances. It affects configurations running as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. The flaw allows remote, unauthenticated attackers to send crafted requests that trigger a denial-of-service (DoS) by causing unintended control flow. Exploits have been observed in the wild, leading to appliances going offline.
Affected Versions:
Mitigation Recommendation:
Apply the Citrix patches immediately: