Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX
The vulnerability (CWE-119) consists of improper handling of memory buffer boundaries in several device configurations. The error occurs when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, as well as when an HTTP, SSL, or HTTP_QUIC load balancing virtual server is associated with IPv6 services or IPv6 service groups (including DBS). An additional attack vector concerns CR virtual server with HDX type. Buffer overflow in these network traffic processing paths can lead to writing data outside the allocated memory area, which an attacker can exploit to hijack control of the execution flow.
A remote, unauthenticated attacker may be able to achieve arbitrary code execution on the vulnerable device (RCE) or cause its complete unavailability through process crash (DoS), which in the case of VPN/Gateway devices may result in disruption of remote access for the entire organization.
Security patches available from the vendor must be applied according to references — Citrix security bulletin CTX694938 (https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938). Due to active exploitation of the vulnerability in production environments (CISA KEV), the update should be deployed immediately. Until patching is completed, consider restricting access to management interfaces and monitoring for anomalies in network traffic on NetScaler devices.
Citrix NetScaler ADC and NetScaler Gateway in versions 13.1, 14.1, 13.1-FIPS and NDcPP, configured as: Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual server, LB virtual server type HTTP/SSL/HTTP_QUIC associated with IPv6 services or service groups (including IPv6 DBS), or CR virtual server with HDX type
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCitrix Netscaler Application Delivery Controller
APPCitrix12.1 – 12.1-55.330 (excl.)13.1 – 13.1-37.241 (excl.)13.1 – 13.1-59.22 (excl.)14.1 – 14.1-47.48 (excl.)Citrix Netscaler Gateway
APPCitrix13.1 – 13.1-59.22 (excl.)14.1 – 14.1-47.48 (excl.)
CISA KEV — detailsi
- Vendori
- Citrix ↗
- Producti
- NetScaler
- Added to KEVi
- August 26, 2025
- Remediation deadline (US Federal)i
- August 28, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
Related vulnerabilities
Citrix NetScaler ADC/Gateway — memory overread przez SAML IDP
Przepełnienie pamięci w Citrix NetScaler ADC i Gateway – RCE/DoS przez VPN
CitrixBleed 2 — memory overread w Citrix NetScaler ADC i Gateway
Citrix Bleed – wyciek tokenów sesji w NetScaler ADC i Gateway
Nieuwierzytelniony RCE w Citrix NetScaler ADC i Gateway