CVE-2026-13474

Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

  • Published Jun 30, 2026
  • CVSS 8.7 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-13474 at the National Vulnerability Database