Junglewise Threat Intelligence

CVE-2026-13474: NetScaler ADC and Gateway denial of service via malformed HTTP/2 requests

CVE-2026-13474 · Severity: info · CVSS 8.7 · Published 2026-06-30

Technologies: NetScaler Gateway, NetScaler ADC.

Executive brief

NetScaler ADC and Gateway appliances are vulnerable to a denial-of-service attack that can crash the system or disrupt network traffic. An attacker can trigger this by sending specially crafted web requests if the HTTP/2 protocol is enabled on the device. This could lead to significant downtime for applications and remote access services relying on these controllers.

Technical details

A denial-of-service vulnerability exists in NetScaler ADC and NetScaler Gateway due to improper memory management (CWE-401) when handling malformed HTTP/2 requests. The issue occurs when HTTP/2 is enabled in the HTTP Profile and associated with a virtual server (LB, CS, or VPN) or a configured service. A remote, unauthenticated attacker can exploit this by sending crafted HTTP/2 traffic, leading to resource exhaustion or service instability. Patches are available for versions 14.1 and 13.1, including FIPS-validated editions.

Affected products

  • NetScaler ADC 14.1 before 72.61, 13.1 before 63.18, 14.1 FIPS before 72.61, 13.1 FIPS and NDcPP before 37.272
  • NetScaler Gateway 14.1 before 72.61, 13.1 before 63.18

Timeline

  • 2026-06-30: advisory: Initial disclosure by NetScaler/Citrix
  • 2026-06-30: disclosed

References