Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3377 articles · 169024 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-13474EXPLOITEDPATCHED
citrix · adc

Denial of service via malformed HTTP/2 requests

Description

A vulnerability classified as problematic has been found in Citrix NetScaler ADC and NetScaler Gateway. This affects an unknown part. The manipulation leads to memory leak. This vulnerability is traded as CVE-2026-13474. It is possible to initiate the attack remotely.

Affected Products

VendorProductVersions
citrixadc14.1, 13.1, 14.1 FIPS, 13.1 FIPS and NDcPP, 14.1, 13.1

References

  • https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Related News (2 articles)

Tier B
CCCS Canada5h ago
Citrix security advisory (AV26-645)
→ No new info (linked only)
Tier C
VulDB7h ago
CVE-2026-13474 | Citrix NetScaler ADC/NetScaler Gateway memory leak (CTX696604)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
72.6163.1837.272
CWECWE-401
PublishedJun 30, 2026
Last enriched6h agov2
Trending Score67
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-8451EXP
Insufficient input validation leading to memory overread
Trending: 79
HIGHCVE-2026-8452EXP
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Trending: 67
HIGHCVE-2026-8655
Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service
Trending: 48
HIGHCVE-2026-10817
Insufficient input validation leading to memory overread
Trending: 48
CRITICALCVE-2026-10816
Arbitrary File Read (Unauthenticated)
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Actively Exploited
Jun 30, 2026
Patch Available
Jun 30, 2026
Updated: description, severity, activelyExploited
Jun 30, 2026

Version History

v2
Last enriched 6h ago
v2Tier C6h ago

Updated description with details about a memory leak vulnerability, changed severity to HIGH, and noted that the vulnerability is actively exploited.

descriptionseverityactivelyExploited
via VulDB
v19h ago

Initial creation