Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
ID: b289397e-4e46-5006-a575-09741da45dd2
STIX ID: report--b289397e-4e46-5006-a575-09741da45dd2
Feed Name: GBHackers
### Executive Summary Cloud Software Group (Citrix) published bulletin CTX696734 on July 14, 2026 disclosing two vulnerabilities in Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows: CVE-2026-53565 (privilege management flaw allowing escalation to SYSTEM, CVSS v4.0 8.5) and CVE-2026-53566 (out-of-bounds memory read, CVSS v4.0 6.8). Affected versions are Secure Access Client prior to 26.6.1.20 and Endpoint Analysis Client prior to 26.5.1.7; fixed releases are 26.6.1.20 and 26.5.1.7 respectively. Citrix urges immediate patching, and recommends compensating controls (review DNE driver status, restrict local user privileges) for organizations that cannot patch immediately; no evidence of active exploitation was provided at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
