Junglewise Threat Intelligence

CVE-2026-53566: Citrix Secure Access Client for Windows out-of-bounds read

CVE-2026-53566 · Severity: info · CVSS 6.8 · Published 2026-07-14

Vendors: Citrix.

Executive brief

Citrix Secure Access Client is a software tool used by employees to securely connect to corporate networks and applications from their Windows computers. A security flaw has been identified that could allow a user who already has limited access to a computer to read sensitive information from the software's memory that they should not be able to see. This could potentially lead to the exposure of internal system details or user credentials, though it requires the attacker to already have a foothold on the local machine.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Citrix Secure Access Client for Windows prior to version 26.6.1.20. The flaw occurs when the application reads data past the end of the intended buffer, which can be triggered by a local attacker with low privileges. Successful exploitation allows the attacker to read sensitive information from the process memory, potentially leading to a loss of confidentiality. The vulnerability is addressed in version 26.6.1.20 and later.

Affected products

  • Citrix Citrix Secure Access Client for Windows before 26.6.1.20

Timeline

  • 2026-07-14: advisory: Initial disclosure by Citrix and NVD publication.
  • 2026-07-14: patched: Fixed in version 26.6.1.20.

References