Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors

Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors

Posted on August 12, 2025August 12, 2025 By CWS

Aug 12, 2025Ravie LakshmananVulnerability / Menace Intelligence
The Dutch Nationwide Cyber Safety Centre (NCSC-NL) has warned of cyber assaults exploiting a lately disclosed vital safety flaw impacting Citrix NetScaler ADC merchandise to breach organizations within the nation.
The NCSC-NL stated it found the exploitation of CVE-2025-6543 concentrating on a number of vital organizations throughout the Netherlands, and that investigations are ongoing to find out the extent of the impression.
CVE-2025-6543 (CVSS rating: 9.2) is a vital safety vulnerability in NetScaler ADC that ends in unintended management stream and denial-of-service (DoS) when the gadgets are configured as a Gateway (VPN digital server, ICA Proxy, CVPN, RDP Proxy) OR AAA digital server.

The vulnerability was first disclosed in late June 2025, with patches launched within the following variations –

NetScaler ADC and NetScaler Gateway 14.1 previous to 14.1-47.46
NetScaler ADC and NetScaler Gateway 13.1 previous to 13.1-59.19
NetScaler ADC 13.1-FIPS and NDcPP previous to 13.1-37.236-FIPS and NDcPP

As of June 30, 2025, CVE-2025-6543 has been added to the U.S. Cybersecurity and Infrastructure Safety Company’s (CISA) Recognized Exploited Vulnerabilities (KEV) catalog. One other flaw in the identical product (CVE-2025-5777, CVSS rating: 9.3) was additionally positioned on the checklist final month.
NCSC-NL described the exercise as possible the work of a complicated menace actor, including the vulnerability has been exploited as a zero-day since early Could 2025 – nearly two months earlier than it was publicly disclosed – and the attackers took steps to erase traces in an effort to hide the compromise. The exploitation was found on July 16, 2025.
“Through the investigation, malicious internet shells had been discovered on Citrix gadgets,” the company stated. “An online shell is a chunk of rogue code that provides an attacker distant entry to the system. The attacker can place an online shell by abusing a vulnerability.”
To mitigate the chance arising from CVE-2025-6543, organizations are suggested to use the newest updates, and terminate everlasting and energetic periods by working the next instructions –

kill icaconnection -all
kill pcoipConnection -all
kill aaa session -all
kill rdp connection -all
clear lb persistentSessions

Organizations can even run a shell script made accessible by NCSC-NL to hunt for indicators of compromise related to the exploitation of CVE-2025-6543.
“Information with a special .php extension in Citrix NetScaler system folders could also be a sign of abuse,” NCSC-NL stated. “Test for newly created accounts on the NetScaler, and particularly for accounts with elevated rights.”

The Hacker News Tags:Active, Citrix, Confirms, Critical, CVE20256543, Dutch, Exploitation, NCSC, NetScaler, Sectors

Post navigation

Previous Post: Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations
Next Post: Apache bRPC Vulnerability Allows Attackers to Crash the Service via Network

Related Posts

SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers SonicWall Urges Password Resets After Cloud Backup Breach Affecting Under 5% of Customers The Hacker News
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto The Hacker News
Enterprise Browsers vs. Secure Browser Extensions Enterprise Browsers vs. Secure Browser Extensions The Hacker News
What 2025 Is Teaching Us About Cloud Defense What 2025 Is Teaching Us About Cloud Defense The Hacker News
New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1–5 CPUs The Hacker News
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark