Description
Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows.

This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption potentially causing application crashes
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds write flaw exists in Citrix Workspace app for Windows. The vulnerability permits a malicious actor to write data beyond the intended buffer limits, which can corrupt adjacent memory. According to the CVE description, this leads to unpredictable behavior such as application crashes or loss of stability. No explicit mention of privilege escalation, data exfiltration, or denial of service to other services is provided, so the impact is limited to the affected application itself.

Affected Systems

Citrix Workspace app for Windows versions before 2603.11 (Current Release), before 2507.1 LTSR CU3, and before LTSR 2607 are affected.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity. The EPSS score of less than 1 % and the lack of a listing in the CISA KEV catalog suggest a low likelihood of active exploitation. An attack vector is not explicitly documented; it can be inferred that the flaw might be triggered by a user or attacker supplying crafted data within the Workspace app or manipulating a session over a remote connection, but no confirmed public exploits are known.

Generated by OpenCVE AI on September 21, 2026 at 04:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Citrix Workspace app to version 2603.11 or later (or 2507.1 LTSR CU3/LTS, or 2607) to eliminate the buffer overflow.
  • If an upgrade is not immediately feasible, constrain the app’s exposure by restricting traffic to trusted Citrix servers and applying network segmentation to isolate endpoints from untrusted sources.
  • Continuously monitor affected endpoints for application crashes or unusual memory usage patterns, as these may indicate attempted exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 04:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix citrix Workspace App For Windows
Vendors & Products Citrix
Citrix citrix Workspace App For Windows

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Title Out-of-Bounds Write
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 4.4, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Citrix Citrix Workspace App For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2026-09-11T19:34:31.103Z

Reserved: 2026-08-24T18:48:00.120Z

Link: CVE-2026-78547

cve-icon Vulnrichment

Updated: 2026-09-11T19:34:28.134Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T20:18:53.757

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-78547

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses