CVE-2026-13474

HIGHCVSS 7.51% EPSS

Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

Published 2026-06-30 · last modified 2026-07-02

Affected products

VendorProduct
citrixnetscaler_application_delivery_controller
citrixnetscaler_gateway

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.