imPC@ndo IT

Tracker / CVE-2026-13474

CVE-2026-13474

High 7.5

Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

Affected products and versions

citrix netscaler_application_delivery_controller
citrix netscaler_application_delivery_controller · … → 13.1-37.272
citrix netscaler_application_delivery_controller · 13.1 → 13.1-63.18
citrix netscaler_application_delivery_controller · 14.1 → 14.1-72.61
citrix netscaler_gateway · 13.1 → 13.1-63.18
citrix netscaler_gateway · 14.1 → 14.1-72.61

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References