Security updates addressing vulnerabilities in Citrix products have been released.
The affected products are Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.
Two vulnerabilities have been addressed.
CVE-2026-53565 is a local privilege escalation vulnerability in Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.
CVE-2026-53566 is an out-of-bounds memory read vulnerability affecting Citrix Secure Access Client for Windows.
The Affected Versions are as follows.
CVE-2026-53565: Citrix Secure Access Client for Windows prior to version 26.6.1.20 And Citrix Endpoint Analysis Client for Windows prior to version 26.5.1.7.
CVE-2026-53566: Citrix Secure Access Client for Windows versions prior to 26.6.1.20.
Vulnerability Patches have been released in the latest updates; you must update to the latest patched version following the instructions on the reference site.
The versions requiring the patch are as follows:
CVE-2026-53565: Citrix Secure Access Client for Windows version 26.6.1.20 Or later, and Citrix Endpoint Analysis Client for Windows version 26.5.1.7 Or later.
CVE-2026-53566: Citrix Secure Access Client for Windows 26.6.1.20 Or later.
For more information, see the Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows Security Bulletin for CVE-2026-53565 and CVE-2026-53566.