Executive brief
Citrix NetScaler ADC and Gateway, which are used to manage network traffic and provide secure remote access (VPN), contain a critical vulnerability. An attacker can exploit this flaw to take control of the device or crash it, potentially leading to a total service outage or unauthorized access to corporate resources. This vulnerability is reportedly being exploited in the wild, making immediate patching essential.
Technical details
A memory overflow vulnerability (CWE-119) exists in Citrix NetScaler ADC and NetScaler Gateway. The flaw is triggered when the device is configured as a Gateway (VPN, ICA Proxy, CVPN, RDP Proxy), an AAA virtual server, or when Load Balancing (LB) virtual servers (HTTP, SSL, or HTTP_QUIC) are bound with IPv6 services. An unauthenticated remote attacker can exploit this to achieve remote code execution (RCE) or cause a denial of service (DoS). The vulnerability is confirmed to be exploited in the wild and is listed in the CISA KEV catalog. Patches are available in versions 13.1-59.22, 14.1-47.48, and updated FIPS/NDcPP releases.
Affected products
- Citrix NetScaler ADC 13.1 before 13.1-59.22, 14.1 before 14.1-47.48, 12.1/13.1 FIPS/NDcPP before fixed versions
- Citrix NetScaler Gateway 13.1 before 13.1-59.22, 14.1 before 14.1-47.48
Timeline
- 2025-08-26: disclosed: Initial disclosure by Citrix and NVD publication
- 2025-08-26: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-08-26: exploited: Reported as exploited in the wild at time of disclosure