
[CIVN-2026-0378] Multiple vulnerabilities in Citrix Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in Citrix Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Citrix Secure Access Client for Windows versions prior to 26.6.1.20
Citrix Endpoint Analysis Client for Windows versions prior to 26.5.1.7
Overview
Multiple vulnerabilities have been reported in Citrix products, which could allow a local, low-privileged attacker to escalate privileges to SYSTEM level or disclose sensitive information from process memory on the affected system.
Target Audience:
All end-user organizations and individuals using affected Citrix products.
Risk Assessment:
Risk of local privilege escalation and sensitive information disclosure.
Impact Assessment:
Potential for elevation of privileges to SYSTEM level resulting in full compromise and disclosure of sensitive information from memory.
Description
Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows are endpoint software components that facilitate secure remote connectivity and endpoint security validation for enterprise environments by verifying device compliance before granting access to organizational resources.
Multiple vulnerabilities exist in these Citrix products due to improper privilege management and an out-of-bounds memory read flaw.
Successful exploitation of these vulnerabilities could allow a local, low-privileged attacker to escalate privileges to SYSTEM level or disclose sensitive information from process memory on the affected system.
Solution
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734
Vendor Information
Citrix
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734
CVE Name
CVE-2026-53565
CVE-2026-53566
—
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpjbqcACgkQ3jCgcSdc
ys+81g/+N9/Xt7JujfrfhbSs0FmoA6Zkyfc9zFEhY/ZQCzUr5ygpnqQLcoPgbSAL
XzSnY5IAOOHF+nabzWmjI9E+ovalugdgJZI1SrlhptsmxzdwInJTsNknhIu2vb/r
QWKEazE92gKi5rPmCrZHSNvwXsrntGW4YVlfNhD5pEQOBYDidyi8BPKBjljPz6W0
Mwji7I2Rf0BRupztKPkfIGjnMNErrtDsOSm4qkhJXJgJiuObrp67MLtxVXlrQSOd
xigoBdY5v54ozdj4pPPSwmK2DC3QKyl0XZqyyHnqYCsUi0Tn1XMBgsYpIjwzOYeT
vwrUNahOBsfvuwCLc5/DPVCBsGo+Px1XaFv1+Xpl1jIPokOpPlujH0dbJeXD2wVX
le5DMns7u20cM2ElHAE7ZwTccuOYL4DYLD2uf4vpIYscWk6o+sloZLcV7tE4GrkS
H5fapZzm1NW7S4uYE5X/FsX3kKWV90nca3e2frm/qInC5K/sWYlRtR7IPbAM8eOI
QRanMKeLQEA6OAQ+06w0XGCrbK2a8u5ta1Gdw18DcTr1vS7eUHLz3M8q6sU/jvt7
oAi35qHTgXDOZqBCxnaEeIaiXlQVs3QZoIYtriRK9FSoK6nNKjsExQt330aod1Ge
lBqKTn5Jyd+jaByPGChH47/FtEM6sEe7LIH3PDjKUbnTmaTNbsc=
=x6KH
—–END PGP SIGNATURE—–


