Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors

The Hacker News by The Hacker News
August 12, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Aug 12, 2025Ravie LakshmananVulnerability / Threat Intelligence

The Dutch National Cyber Security Centre (NCSC-NL) has warned of cyber attacks exploiting a recently disclosed critical security flaw impacting Citrix NetScaler ADC products to breach organizations in the country.

The NCSC-NL said it discovered the exploitation of CVE-2025-6543 targeting several critical organizations within the Netherlands, and that investigations are ongoing to determine the extent of the impact.

CVE-2025-6543 (CVSS score: 9.2) is a critical security vulnerability in NetScaler ADC that results in unintended control flow and denial-of-service (DoS) when the devices are configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

Cybersecurity

The vulnerability was first disclosed in late June 2025, with patches released in the following versions –

  • NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-47.46
  • NetScaler ADC and NetScaler Gateway 13.1 prior to 13.1-59.19
  • NetScaler ADC 13.1-FIPS and NDcPP prior to 13.1-37.236-FIPS and NDcPP

As of June 30, 2025, CVE-2025-6543 has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog. Another flaw in the same product (CVE-2025-5777, CVSS score: 9.3) was also placed on the list last month.

NCSC-NL described the activity as likely the work of a sophisticated threat actor, adding the vulnerability has been exploited as a zero-day since early May 2025 – almost two months before it was publicly disclosed – and the attackers took steps to erase traces in an effort to conceal the compromise. The exploitation was discovered on July 16, 2025.

“During the investigation, malicious web shells were found on Citrix devices,” the agency said. “A web shell is a piece of rogue code that gives an attacker remote access to the system. The attacker can place a web shell by abusing a vulnerability.”

To mitigate the risk arising from CVE-2025-6543, organizations are advised to apply the latest updates, and terminate permanent and active sessions by running the following commands –

  • kill icaconnection -all
  • kill pcoipConnection -all
  • kill aaa session -all
  • kill rdp connection -all
  • clear lb persistentSessions
Identity Security Risk Assessment

Organizations can also run a shell script made available by NCSC-NL to hunt for indicators of compromise associated with the exploitation of CVE-2025-6543.

“Files with a different .php extension in Citrix NetScaler system folders may be an indication of abuse,” NCSC-NL said. “Check for newly created accounts on the NetScaler, and specifically for accounts with increased rights.”



Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
UK state-owned bank goes cloud-native | Computer Weekly

UK state-owned bank goes cloud-native | Computer Weekly

Recommended.

DNAKE bringt H618 Pro auf den Markt: Branchenweit erster Android 15-Innenmonitor für intelligente Gegensprechanlagen

DNAKE bringt H618 Pro auf den Markt: Branchenweit erster Android 15-Innenmonitor für intelligente Gegensprechanlagen

August 21, 2025
Rethink authentication to remove the burden on users | Computer Weekly

Rethink authentication to remove the burden on users | Computer Weekly

April 23, 2025

Trending.

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More

October 6, 2025
Cloud Computing on the Rise: Market Projected to Reach .6 Trillion by 2030

Cloud Computing on the Rise: Market Projected to Reach $1.6 Trillion by 2030

August 1, 2025
Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

Stocks making the biggest moves midday: Autodesk, PayPal, Rivian, Nebius, Waters and more

July 14, 2025
The Ultimate MSP Guide to Structuring and Selling vCISO Services

The Ultimate MSP Guide to Structuring and Selling vCISO Services

February 19, 2025
Translators’ Voices: China shares technological achievements with the world for mutual benefit

Translators’ Voices: China shares technological achievements with the world for mutual benefit

June 3, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio