CVE-2026-13474: Citrix NetScaler Application Delivery Controller

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

Affected products

  • Citrix NetScaler Application Delivery Controller: before 13.1-37.272 (fixed in 13.1-37.272); from 13.1, before 13.1-63.18 (fixed in 13.1-63.18); from 14.1, before 14.1-72.61 (fixed in 14.1-72.61); version 14.1-66.68 only
  • Citrix NetScaler Gateway: from 13.1, before 13.1-63.18 (fixed in 13.1-63.18); from 14.1, before 14.1-72.61 (fixed in 14.1-72.61)

Published 2026-06-30. Last modified 2026-07-02.