[CIVN-2026-0378] Multiple vulnerabilities in Citrix Products

By Published On: July 24, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple vulnerabilities in Citrix Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)




Severity Rating: HIGH


Software Affected




Citrix Secure Access Client for Windows versions prior to 26.6.1.20


Citrix Endpoint Analysis Client for Windows versions prior to 26.5.1.7


Overview




Multiple vulnerabilities have been reported in Citrix products, which could allow a local, low-privileged attacker to escalate privileges to SYSTEM level or disclose sensitive information from process memory on the affected system.




Target Audience:


All end-user organizations and individuals using affected Citrix products.




Risk Assessment:


Risk of local privilege escalation and sensitive information disclosure.




Impact Assessment:


Potential for elevation of privileges to SYSTEM level resulting in full compromise and disclosure of sensitive information from memory.




Description




Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows are endpoint software components that facilitate secure remote connectivity and endpoint security validation for enterprise environments by verifying device compliance before granting access to organizational resources.




Multiple vulnerabilities exist in these Citrix products due to improper privilege management and an out-of-bounds memory read flaw.




Successful exploitation of these vulnerabilities could allow a local, low-privileged attacker to escalate privileges to SYSTEM level or disclose sensitive information from process memory on the affected system.




Solution


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734






Vendor Information


Citrix


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734




References


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734




CVE Name


CVE-2026-53565


CVE-2026-53566




 —




Thanks and Regards,


CERT-In




Incident Response Help Desk


e-mail: incident@cert-in.org.in


Phone: +91-11-22902657


Toll Free Number: 1800-11-4949


Toll Free Fax : 1800-11-6969


Web: http://www.cert-in.org.in


PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4


PGP Key information:


https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS




Postal address:


Indian Computer Emergency Response Team (CERT-In)


Ministry of Electronics and Information Technology


Government of India


Electronics Niketan


6, C.G.O. Complex


New Delhi-110 003


—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpjbqcACgkQ3jCgcSdc

ys+81g/+N9/Xt7JujfrfhbSs0FmoA6Zkyfc9zFEhY/ZQCzUr5ygpnqQLcoPgbSAL

XzSnY5IAOOHF+nabzWmjI9E+ovalugdgJZI1SrlhptsmxzdwInJTsNknhIu2vb/r

QWKEazE92gKi5rPmCrZHSNvwXsrntGW4YVlfNhD5pEQOBYDidyi8BPKBjljPz6W0

Mwji7I2Rf0BRupztKPkfIGjnMNErrtDsOSm4qkhJXJgJiuObrp67MLtxVXlrQSOd

xigoBdY5v54ozdj4pPPSwmK2DC3QKyl0XZqyyHnqYCsUi0Tn1XMBgsYpIjwzOYeT

vwrUNahOBsfvuwCLc5/DPVCBsGo+Px1XaFv1+Xpl1jIPokOpPlujH0dbJeXD2wVX

le5DMns7u20cM2ElHAE7ZwTccuOYL4DYLD2uf4vpIYscWk6o+sloZLcV7tE4GrkS

H5fapZzm1NW7S4uYE5X/FsX3kKWV90nca3e2frm/qInC5K/sWYlRtR7IPbAM8eOI

QRanMKeLQEA6OAQ+06w0XGCrbK2a8u5ta1Gdw18DcTr1vS7eUHLz3M8q6sU/jvt7

oAi35qHTgXDOZqBCxnaEeIaiXlQVs3QZoIYtriRK9FSoK6nNKjsExQt330aod1Ge

lBqKTn5Jyd+jaByPGChH47/FtEM6sEe7LIH3PDjKUbnTmaTNbsc=

=x6KH

—–END PGP SIGNATURE—–

Share this article