Citrix Security Update – 15 July 2026

Citrix has released a security update to address multiple vulnerabilities affecting Citrix Secure Access Client, Citrix Endpoint Analysis Client for Windows, and XenCenter.

The addressed vulnerabilities could allow the attacker to gain elevated privileges or obtain sensitive information on the affected product.

Sample of the addressed vulnerabilities:

1. Citrix Endpoint Analysis Client Improper Privilege Management Vulnerability (CVE-2026-53565):

  • CVSS 4.0: 8.5
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

2. Citrix Secure Access Client Out-of-Bounds Memory Read Vulnerability (CVE- 2026-53566):

  • CVSS 4.0: 6.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2026-53565
  • CVE-2026-53566
  • CVE-2026-42491
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Citrix Security Advisory

References