Description
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows.

This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
Published: 2026-07-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds memory read in Citrix Secure Access Client for Windows. Because the client attempts to read data beyond the intended buffer, an attacker who can trigger the flaw may access sensitive information stored nearby in memory, leading to accidental disclosure of potentially confidential data. The weakness corresponds to CWE‑125, which reflects a non‑code‑execution read flaw that can compromise confidentiality but does not result in arbitrary code execution or denial of service. The impact is limited to data leakage rather than system compromise.

Affected Systems

Citrix Secure Access Client for Windows, versions prior to 26.6.1.20, is the affected product for Citrix. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS base score of 6.8 places the flaw in the medium to high risk range, indicating that while the vulnerability can be leveraged, it does not automatically grant privileged access. The EPSS score of less than 1 % suggests a very low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is not explicitly documented in the available data; based on the nature of the client software and the type of flaw, it is inferred that a local or privileged user could potentially exploit the read if they can influence the client’s memory usage, or a remote attacker may succeed by sending specially crafted input if the client processes network data without proper bounds checking.

Generated by OpenCVE AI on July 31, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Citrix Secure Access Client to version 26.6.1.20 or later, which contains the fix for the out‑of‑bounds read.
  • If an update is not immediately possible, isolate the client hosts from untrusted networks and restrict administrative privileges to reduce the attack surface.
  • Disable any unnecessary client features that may utilize the vulnerable memory paths, and enable endpoint protection to detect and prevent anomalous memory read patterns.

Generated by OpenCVE AI on July 31, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix secure Access Client
Vendors & Products Citrix
Citrix secure Access Client

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
Title Out-of-bounds memory read
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Citrix Secure Access Client
cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2026-07-14T13:56:09.574Z

Reserved: 2026-06-09T18:32:47.375Z

Link: CVE-2026-53566

cve-icon Vulnrichment

Updated: 2026-07-14T13:56:06.817Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses