{"id":6556,"date":"2025-08-31T10:04:35","date_gmt":"2025-08-31T10:04:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/31\/critical-citrix-0-day-vulnerability-exploited-since-may-leaving-global-entities-exposed\/"},"modified":"2025-08-31T10:04:35","modified_gmt":"2025-08-31T10:04:35","slug":"critical-citrix-0-day-vulnerability-exploited-since-may-leaving-global-entities-exposed","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/31\/critical-citrix-0-day-vulnerability-exploited-since-may-leaving-global-entities-exposed\/","title":{"rendered":"Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed"},"content":{"rendered":"<p>    Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical zero-day vulnerability in Citrix NetScaler products, identified as <a href=\"https:\/\/cybersecuritynews.com\/citrix-netscaler-devices-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-6543<\/a>, has been actively exploited by threat actors since at least May 2025, months before a patch was made available.<\/p>\n<p>While Citrix initially downplayed the flaw as a \u201cmemory overflow vulnerability leading to unintended control flow and Denial of Service,\u201d it has since been revealed to allow for unauthenticated remote code execution (RCE), leading to widespread compromise of government and legal services worldwide.<\/p>\n<p>In late June 2025, Citrix released a patch for <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-citrix-netscaler-adc-and-gateway\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-6543<\/a>. However, by that time, attackers had already been leveraging the vulnerability for weeks. <\/p>\n<p>The exploit was used to infiltrate NetScaler remote access systems, deploy webshells to ensure persistent access even after patching, and steal credentials. <\/p>\n<p>Evidence suggests that Citrix was aware of the severity and the ongoing exploitation but failed to disclose the full extent of the threat to its customers, Kevin Beaumont <a href=\"https:\/\/doublepulsar.com\/citrix-forgot-to-tell-you-cve-2025-6543-has-been-used-as-a-zero-day-since-may-2025-d76574e2dd2c\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said<\/a>.<\/p>\n<p>The company provided a script to check for compromise only upon request and under restrictive conditions, without fully explaining the situation or the script\u2019s limitations.<\/p>\n<p>The Dutch National Cyber Security Centre (NCSC) has played a pivotal role in exposing the true nature of the attacks. Their investigation confirmed that the vulnerability was exploited as a zero-day and that attackers actively covered their tracks, making <a href=\"https:\/\/cybersecuritynews.com\/what-is-digital-forensics\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic analysis<\/a> challenging.<\/p>\n<p>The NCSC\u2019s report, released in August 2025, stated that \u201cseveral critical organizations within the Netherlands have been successfully attacked\u201d and that the vulnerability was abused since at least early May.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-the-exploit-works\"><strong>How the Exploit Works<\/strong><\/h2>\n<p>The same sophisticated threat actor is also believed to be behind the exploitation of another zero-day, CVE-2025\u20135777, also known as <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-citrixbleed-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">CitrixBleed 2<\/a>, which was used to steal user sessions.<\/p>\n<p>Investigations are ongoing to determine if this actor is also responsible for exploiting a more recent vulnerability, CVE-2025-7775.<\/p>\n<p>The CVE-2025\u20136543 vulnerability allows an attacker to overwrite system memory by supplying a malicious client certificate to the <code>\/cgi\/api\/login<\/code> endpoint on a vulnerable NetScaler device. <\/p>\n<p>By sending hundreds of these requests, an attacker can overwrite enough memory to execute arbitrary code on the system. This method gives them a foothold in the network, which they have used to move laterally into <a href=\"https:\/\/cybersecuritynews.com\/active-directory-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory<\/a> environments by misusing stolen LDAP service account credentials.<\/p>\n<p>Security professionals urge all organizations using internet-facing Citrix NetScaler devices to take immediate action.<\/p>\n<p>System administrators should check for signs of compromise, which include looking for large POST requests to <code>\/cgi\/api\/login<\/code> in web access logs, often in quick succession.<\/p>\n<p>A corresponding NetScaler log error code of 1245184, indicating an invalid client certificate, is a strong indicator of an exploitation attempt.<\/p>\n<p>The NCSC has released scripts on GitHub to help organizations check for compromise on live hosts and in coredump files.<\/p>\n<p>If a system is believed to be compromised, the recommended steps are:<\/p>\n<ul class=\"wp-block-list\">\n<li>Immediately take the NetScaler device offline.<\/li>\n<li>Image the system for forensic analysis.<\/li>\n<li>Change the LDAP service account credentials to prevent lateral movement.<\/li>\n<li>Deploy a new, patched NetScaler instance with fresh credentials.<\/li>\n<\/ul>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-6543 to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for organizations to apply patches and hunt for signs of malicious activity.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/citrix-0-day-vulnerability-exploited\/\">Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/citrix-0-day-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed A critical zero-day vulnerability in Citrix NetScaler products, identified as CVE-2025-6543, has been actively exploited by threat actors since at least May 2025, months before a patch was made available. While Citrix initially downplayed the flaw as a \u201cmemory overflow vulnerability leading to unintended [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-6556","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6556"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6556"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6556\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6556"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6556"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6556"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}