Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5764 articles · 192448 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-13474EXPLOITEDPATCHED
citrix · netscaler_application_delivery_controller

Denial of service via malformed HTTP/2 requests

Description

A vulnerability classified as problematic has been found in Citrix NetScaler ADC and NetScaler Gateway. This affects an unknown part. The manipulation leads to memory leak. This vulnerability is traded as CVE-2026-13474. It is possible to initiate the attack remotely.

Affected Products

VendorProductVersions
citrixnetscaler_application_delivery_controller14.1, 13.1, 14.1 FIPS, 13.1 FIPS and NDcPP, 14.1, 13.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
citrixnetscalercert_advisory90%
citrixnetscaler_gatewaycve_cpe95%

References

  • https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Related News (4 articles)

Tier B
BSI Advisories47d ago
[NEU] [hoch] Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR47d ago
Multiples vulnérabilités dans les produits Citrix (01 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada48d ago
Citrix security advisory (AV26-645)
→ No new info (linked only)
Tier C
VulDB48d ago
CVE-2026-13474 | Citrix NetScaler ADC/NetScaler Gateway memory leak (CTX696604)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
72.6163.1837.272
CWECWE-401
PublishedJun 30, 2026
Last enriched48d agov2
Trending Score0
Source articles4
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-8452EXPKEV
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Trending: 121
NONECVE-2026-53565
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Trending: 1
HIGHCVE-2026-53566EXP
Out-of-bounds memory read
Trending: 1
CRITICALCVE-2026-8451EXPKEV
Insufficient input validation leading to memory overread
CRITICALCVE-2026-10816
Arbitrary File Read (Unauthenticated)

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Actively Exploited
Jun 30, 2026
Patch Available
Jun 30, 2026
Updated: description, severity, activelyExploited
Jun 30, 2026

Version History

v2
Last enriched 48d ago
v2Tier C48d ago

Updated description with details about a memory leak vulnerability, changed severity to HIGH, and noted that the vulnerability is actively exploited.

descriptionseverityactivelyExploited
via VulDB
v148d ago

Initial creation