
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13474 is a denial-of-service vulnerability in Citrix NetScaler ADC and NetScaler Gateway caused by improper handling of malformed HTTP/2 requests. It is exploitable when HTTP/2 is enabled in an HTTP Profile and associated with a virtual server (of type LB, CS, or VPN) or a service configured on NetScaler. Affected versions include NetScaler ADC and Gateway 13.1 before 13.1-63.18, 14.1 before 14.1-72.61, ADC 13.1 FIPS/NDcPP before 13.1-37.272, and ADC 14.1 FIPS before 14.1-72.61. The vulnerability was published on June 30, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Citrix Advisory).
The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), indicating that the NetScaler HTTP/2 processing code fails to properly release allocated memory when handling malformed HTTP/2 requests, leading to resource exhaustion. The attack vector is network-based, requires no authentication, no user interaction, and no special privileges — making it fully unauthenticated and remotely exploitable. Exploitation is only possible when HTTP/2 is explicitly enabled in an HTTP Profile and that profile is bound to a virtual server (LB, CS, or VPN type) or a service on the appliance. No public proof-of-concept code has been identified at this time (GitHub Advisory, Citrix Advisory).
Successful exploitation causes a denial-of-service condition on the affected NetScaler ADC or Gateway instance, making load balancing, content switching, and VPN services unavailable to legitimate users. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability of the vulnerable system, with a low secondary availability impact on subsequent systems. For organizations relying on NetScaler as a critical network gateway or application delivery controller, exploitation could result in significant service outages and disruption to enterprise access (GitHub Advisory, Citrix Advisory).
ns.log or httperr.log entries indicating HTTP/2 protocol violations or unexpected connection resets at high frequency.nsppe or HTTP processing daemons on the NetScaler appliance.Citrix has released patched versions addressing CVE-2026-13474: NetScaler ADC and Gateway 13.1-63.18 or later, 14.1-72.61 or later, ADC 13.1-37.272 or later (FIPS/NDcPP), and ADC 14.1-72.61 or later (FIPS). Organizations should upgrade to the appropriate fixed version as the primary remediation (Citrix Advisory). As a temporary workaround prior to patching, administrators should disable HTTP/2 in the HTTP Profile if it is not operationally required, or restrict network access to NetScaler ADC and Gateway services to trusted source IP addresses only. Reviewing all HTTP Profiles bound to virtual servers (LB, CS, VPN) and services to confirm HTTP/2 is only enabled where necessary is also recommended.
Citrix published security bulletin CTX696604 on June 30, 2026, addressing CVE-2026-13474 alongside five other NetScaler vulnerabilities (Citrix Advisory). SecurityWeek described the vulnerability as a new "HTTP/2 bomb" attack technique, drawing attention to the attack pattern's potential for automated, unauthenticated exploitation (SecurityWeek). Government cybersecurity agencies including Canada's CCCS and Singapore's CSA issued advisories urging organizations to apply patches promptly. Multiple security news outlets including The Hacker News, GBHackers, and CyberSecurityNews covered the broader NetScaler patch release, noting the combination of DoS and memory overread vulnerabilities in the same bulletin (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."