Citrix warns of exploitation of Netscaler devices through new bugs
Citrix发现NetScaler产品存在严重漏洞(CVE-2025-6543),评分9.2分,已被利用。建议用户升级软件以应对风险。该漏洞与先前的CVE-2025-5349和CVE-2025-5777可能相关联,专家警告其类似“Citrix Bleed 2”,可能导致敏感数据泄露及多因素认证被绕过。 2025-6-25 20:31:17 Author: therecord.media(查看原文) 阅读量:48 收藏

Hackers are exploiting a new vulnerability affecting several NetScaler products used by companies to manage network traffic.

Citrix published an advisory on Wednesday about CVE-2025-6543, a vulnerability carrying a severity score of 9.2 out of 10 that affects its Netscaler ADC and Netscaler Gateway appliances. The company said exploits of the vulnerability “on unmitigated appliances have been observed.”

Citrix urged customers to install updated versions of the software.

The advisory follows concerns about two other Netscaler vulnerabilities, tagged as CVE-2025-5349 and CVE-2025-5777. In its advisory last week, Citrix did not say if the bugs had already been exploited. 

Researchers have speculated that the three bugs are likely connected but Citrix did not respond to requests for comment. 

Experts compared the vulnerabilities from last week to Citrix Bleed — a widely exploited bug in 2023 that was used by ransomware gangs and nation-states to attack dozens of government organizations and major companies including Boeing and Toyota

Cybersecurity expert Kevin Beaumont, who dubbed the recent bugs as “Citrix Bleed 2,” warned that thousands of NetScaler installations are exposed to the internet. CVE-2025-5349 and CVE-2025-5777 allow threat actors to read sensitive data that could be used to bypass multifactor authentication, he added. 

The U.K.’s National Health Service released its own notice comparing the first two published vulnerabilities to Citrix Bleed, reiterating that the 2023 bug was heavily exploited by ransomware gangs. 

CVE-2025-5777 could expose “sensitive information such as session tokens,” the NHS said. 

“Attackers could use these tokens to hijack existing sessions, allowing access into the network, bypassing authentication controls such as multi-factor authentication (MFA),” they added. 

The original Citrix Bleed bug caused alarm among defenders because of how many hospitals and critical infrastructure organizations use NetScaler ADC and NetScaler Gateway.

The U.S. Cybersecurity and Infrastructure Security Agency warned more than 300 organizations in 2023 of their exposure to Citrix Bleed.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/citrix-warns-netscaler-exploitation-bug
如有侵权请联系:admin#unsafe.sh