CVE-2026-13474
No known exploitation. EPSS puts it in the 44th percentile. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether your NetScaler ADC or NetScaler Gateway has HTTP/2 enabled in the HTTP Profile and is associated with any active load-balancing, content switching, or VPN virtual server/service.
- Verify your current software version on the affected NetScaler device (ADC and/or Gateway).
- Upgrade to a fixed release: for both ADC and Gateway, move to 72.61 or 63.18 or 37.272 (choose the highest available fixed version that fits your environment).
- If you cannot upgrade right away, disable HTTP/2 in the relevant HTTP Profile(s) used by those virtual server/service bindings, then test that client connectivity still works.
What it is
From the CVE record
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
In plain language
Written by AI from the recordIf you use NetScaler ADC or NetScaler Gateway with HTTP/2 turned on, a bad HTTP/2 request could knock the service offline; small businesses should patch, especially if your device is internet-facing.
Denial of service in NetScaler ADC/Gateway when malformed HTTP/2 requests are processed while HTTP/2 is enabled in the HTTP Profile and bound to the relevant virtual server/service, potentially exhausting or crashing request handling.
If you're affected
- Website and app downtime
- Login and access disruption
- Service interruptions for customers
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
0.6% chance of exploitation activity in the next 30 days, which ranks it in the 44th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
5 events over 15 days, from the signal feeds we watch.
- OpenVAS check added
- Patch availablerecord updated
- Publishedweakness classified
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Scored 7.5 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality NoneNo confidentiality impact
- Integrity NoneNo integrity impact
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
Sources
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for ADC, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI