CVE-2026-13474
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-13474 is a denial-of-service vulnerability in Citrix NetScaler ADC and NetScaler Gateway caused by improper handling of malformed HTTP/2 requests. It is exploitable when HTTP/2 is enabled in an HTTP Profile and associated with a virtual server (of type LB, CS, or VPN) or a service configured on NetScaler. Affected versions include NetScaler ADC and Gateway 13.1 before 13.1-63.18, 14.1 before 14.1-72.61, ADC 13.1 FIPS/NDcPP before 13.1-37.272, and ADC 14.1 FIPS before 14.1-72.61. The vulnerability was published on June 30, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Citrix Advisory).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), indicating that the NetScaler HTTP/2 processing code fails to properly release allocated memory when handling malformed HTTP/2 requests, leading to resource exhaustion. The attack vector is network-based, requires no authentication, no user interaction, and no special privileges — making it fully unauthenticated and remotely exploitable. Exploitation is only possible when HTTP/2 is explicitly enabled in an HTTP Profile and that profile is bound to a virtual server (LB, CS, or VPN type) or a service on the appliance. No public proof-of-concept code has been identified at this time (GitHub Advisory, Citrix Advisory).

Impact

Successful exploitation causes a denial-of-service condition on the affected NetScaler ADC or Gateway instance, making load balancing, content switching, and VPN services unavailable to legitimate users. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability of the vulnerable system, with a low secondary availability impact on subsequent systems. For organizations relying on NetScaler as a critical network gateway or application delivery controller, exploitation could result in significant service outages and disruption to enterprise access (GitHub Advisory, Citrix Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing NetScaler ADC or Gateway instances running vulnerable versions (13.1 < 63.18 or 14.1 < 72.61) using tools such as Shodan or Censys, filtering for Citrix/NetScaler banners.
  2. Confirm HTTP/2 enablement: Probe the target to determine if HTTP/2 is supported and enabled on the virtual server (LB, CS, or VPN type) by sending an HTTP/2 upgrade or direct HTTP/2 connection attempt.
  3. Craft malformed HTTP/2 requests: Construct specially malformed HTTP/2 frames (e.g., oversized HEADERS frames, invalid CONTINUATION frames, or resource-exhausting SETTINGS floods) designed to trigger the memory management flaw in the NetScaler HTTP/2 parser.
  4. Send requests to trigger DoS: Repeatedly send the malformed HTTP/2 requests to the target virtual server or service endpoint, causing memory to be allocated but not released, progressively exhausting available memory.
  5. Achieve denial of service: The NetScaler service crashes or becomes unresponsive, denying access to legitimate users of the load balancer, content switch, or VPN gateway (GitHub Advisory, Citrix Advisory).

Indicators of compromise

  • Network: Unusual volume of HTTP/2 connections or malformed HTTP/2 frames (e.g., oversized HEADERS, invalid CONTINUATION, or SETTINGS flood) originating from a single or small set of external IP addresses targeting NetScaler virtual server ports (typically 443).
  • Network: Sudden spike in inbound HTTP/2 traffic without corresponding legitimate user activity.
  • Logs: NetScaler system logs showing repeated HTTP/2 parsing errors, memory allocation failures, or process crashes around the same time as traffic anomalies.
  • Logs: NetScaler ns.log or httperr.log entries indicating HTTP/2 protocol violations or unexpected connection resets at high frequency.
  • Process/System: Unexpected restarts of the nsppe or HTTP processing daemons on the NetScaler appliance.
  • System: Elevated memory utilization on the NetScaler appliance trending toward exhaustion without a corresponding increase in legitimate traffic load.

Mitigation and workarounds

Citrix has released patched versions addressing CVE-2026-13474: NetScaler ADC and Gateway 13.1-63.18 or later, 14.1-72.61 or later, ADC 13.1-37.272 or later (FIPS/NDcPP), and ADC 14.1-72.61 or later (FIPS). Organizations should upgrade to the appropriate fixed version as the primary remediation (Citrix Advisory). As a temporary workaround prior to patching, administrators should disable HTTP/2 in the HTTP Profile if it is not operationally required, or restrict network access to NetScaler ADC and Gateway services to trusted source IP addresses only. Reviewing all HTTP Profiles bound to virtual servers (LB, CS, VPN) and services to confirm HTTP/2 is only enabled where necessary is also recommended.

Community reactions

Citrix published security bulletin CTX696604 on June 30, 2026, addressing CVE-2026-13474 alongside five other NetScaler vulnerabilities (Citrix Advisory). SecurityWeek described the vulnerability as a new "HTTP/2 bomb" attack technique, drawing attention to the attack pattern's potential for automated, unauthenticated exploitation (SecurityWeek). Government cybersecurity agencies including Canada's CCCS and Singapore's CSA issued advisories urging organizations to apply patches promptly. Multiple security news outlets including The Hacker News, GBHackers, and CyberSecurityNews covered the broader NetScaler patch release, noting the combination of DoS and memory overread vulnerabilities in the same bulletin (The Hacker News).

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management