CVE-2026-53565 – Citrix Secure Access Client for Windows
“Endpoint software deserves the same attention as the systems it protects.”
This update addresses two vulnerabilities affecting Citrix Secure Access Client for Windows. CVE-2026-53565 has a CVSS score of 8.5, High severity. It is an Improper Privilege Management vulnerability (CWE-269) that could allow an attacker to gain elevated privileges on affected systems. CVE-2026-53566 has a CVSS score of 6.8, Medium severity. It is an Out-of-Bounds Read vulnerability (CWE-125) that may allow unauthorized memory access. No verified real-world exploitation has been reported for either vulnerability.
The update resolves privilege management and memory handling issues affecting Citrix Secure Access Client for Windows before 26.6.1.20. It also addresses the privilege management vulnerability in Citrix Endpoint Analysis Client for Windows before 26.5.1.7. CVE-2026-53565 has Elevation of Privilege (EoP) characteristics, while CVE-2026-53566 has Remote Code Execution (RCE) characteristics based on the supplied assessment.
Key Details
- CWE Classification
- CWE-269