Threat reportVulnerabilityTL-2026-1474
Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)
Citrix Secure Access and Endpoint Analysis Client for (TL-2026-1474) is a high-severity software vulnerability scored CVSS 8.5, first published 2026-07-18. It has no confirmed attribution, affects Cloud Software Group / Citrix Citrix Secure Access Client for Windows, references 2 CVEs (CVE-2026-53565, CVE-2026-53566), maps to 16 MITRE ATT&CK techniques (T1003, T1005, T1059), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 8.5/10High
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-1474
- Threat ID
- TL-2026-1474
- Severity
- HIGH
- CVSS
- 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- enterprise, government administration, finance, health, technology, remote-workforce
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How Citrix Secure Access and Endpoint Analysis Client for works
Citrix disclosed two local vulnerabilities affecting its Secure Access Client and Endpoint Analysis Client for Windows: CVE-2026-53565, an improper privilege management flaw (CVSS 4.0 8.5) that lets a standard local user escalate to SYSTEM, and CVE-2026-53566, an out-of-bounds memory read (CVSS 4.0 6.8) that discloses sensitive information when the DNE driver is not installed. No public PoC or active exploitation has been confirmed; patches are available.
On July 14, 2026, Cloud Software Group (Citrix) published security bulletin CTX696734 disclosing two local vulnerabilities in Windows client software used for remote-access VPN and endpoint compliance scanning: Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.
CVE-2026-53565 (CWE-269, Improper Privilege Management, CVSS 4.0 base score 8.5, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) affects both clients. A low-privileged local user who already has standard, non-administrative access to the endpoint can abuse a flaw in how the client software manages privileged operations — typical root causes for this class of bug in VPN/endpoint-agent Windows services include an insecure named pipe or IPC channel exposed by a SYSTEM-level service, a privileged helper process that trusts unvalidated input from a lower-integrity client process, or a misconfigured service/driver ACL that allows a standard user to trigger privileged code paths — to escalate local privileges to SYSTEM. Because the affected software runs as a background Windows service/driver stack that is installed with elevated privileges on endpoints across the enterprise (a common deployment pattern for VPN/ZTNA and endpoint-compliance agents), successful exploitation gives an attacker who already has a low-privileged foothold (e.g., via phishing, a compromised user session, or a supply-chain-delivered implant) full SYSTEM-level control of the host — enabling credential dumping, security-tooling tampering, persistence installation, and lateral movement.
CVE-2026-53566 (CWE-125, Out-of-bounds Read, CVSS 4.0 base score 6.8, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N) affects the Citrix Secure Access Client for Windows. It is an out-of-bounds memory read that a standard local user can trigger to disclose sensitive in-memory data (a common consequence class includes leaked pointers, credentials, or other process memory contents that can be leveraged to defeat memory-protection mitigations or as a stepping stone toward further exploitation). Citrix documents this vulnerability's impact as conditional on the DNE (Device/Deterministic Network Enhancer, referred to by Citrix documentation as the DNE driver component bundled with the Secure Access networking stack) driver not being installed on the endpoint; administrators can check DNE driver presence via NetScaler Gateway/Secure Access client configuration documentation.
Both vulnerabilities require only local, standard-user access with no user interaction (UI:N) and low attack complexity (AC:L), making them attractive as a second-stage privilege-escalation primitive following any form of initial access that grants a foothold as a non-administrative user — a very common outcome of phishing, malicious document execution, or compromised low-privilege service accounts.
Citrix credits Carlos Garrido of Pentraze Cybersecurity with discovering and responsibly disclosing both issues. As of this writing there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation; the CVEs do not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Citrix has shipped fixed builds for both affected clients, and remediation is a straightforward client update — no workaround is documented as a substitute for patching the privilege-escalation issue (CVE-2026-53565), while DNE driver installation is noted as a relevant configuration factor for CVE-2026-53566 exposure.
MITRE ATT&CK techniques used in TL-2026-1474
Credential Access
T1003 OS Credential Dumping; T1212 Exploitation for Credential Access
Collection
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism
Discovery
T1082 System Information Discovery; T1518 Software Discovery
Defense Evasion
T1211 Exploitation for Stealth
Impact
Persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Initial Access
defense-impairment
Affected products and versions in Citrix Secure Access and Endpoint Analysis Client for
- Cloud Software Group / Citrix — Citrix Secure Access Client for Windows
Vulnerable versions: versions before 26.6.1.20
Fixed in: 26.6.1.20 and later - Cloud Software Group / Citrix — Citrix Endpoint Analysis Client for Windows
Vulnerable versions: versions before 26.5.1.7 (CVE-2026-53565 only)
Fixed in: 26.5.1.7 and later
Remediation for Citrix Secure Access and Endpoint Analysis Client for
Patches
- Citrix Secure Access Client for Windows 26.6.1.20 (CTX696734)
- Citrix Endpoint Analysis Client for Windows 26.5.1.7 (CTX696734)
Immediate actions
- Upgrade Citrix Secure Access Client for Windows to version 26.6.1.20 or later
- Upgrade Citrix Endpoint Analysis Client for Windows to version 26.5.1.7 or later
- Inventory all Windows endpoints running Citrix Secure Access Client or Citrix Endpoint Analysis Client to identify unpatched versions
- Verify whether the DNE driver is installed on Secure Access Client endpoints to assess exposure to CVE-2026-53566
Workarounds
- No effective workaround beyond patching is documented for CVE-2026-53565
- Removing or not installing the DNE driver component is a documented condition affecting CVE-2026-53566 exposure, per Citrix guidance
Longer-term hardening
- Enforce least-privilege on endpoints so a compromised standard-user session cannot be trivially used as a springboard for local privilege escalation
- Deploy EDR/endpoint monitoring for anomalous SYSTEM-level process spawning from Citrix client service accounts
- Establish a recurring patch-management cadence specifically for VPN/ZTNA and endpoint-compliance client software given their elevated-privilege footprint
- Monitor Citrix security bulletins (support.citrix.com) for follow-on advisories affecting Secure Access and Endpoint Analysis clients
CVEs associated with Citrix Secure Access and Endpoint Analysis Client for
CVE-2026-53565, CVE-2026-53566
Weaknesses (CWE) in Citrix Secure Access and Endpoint Analysis Client for
Timeline of Citrix Secure Access and Endpoint Analysis Client for
- Carlos Garrido of Pentraze Cybersecurity reports the improper privilege management and out-of-bounds read issues to Cloud Software Group / Citrix under responsible disclosure (exact private-disclosure date not published by vendor; placed prior to public bulletin).
- Citrix Secure Access Client for Windows 26.6.1.20 and Citrix Endpoint Analysis Client for Windows 26.5.1.7 are made available to remediate the vulnerabilities.
- Cloud Software Group publishes security bulletin CTX696734 disclosing CVE-2026-53565 and CVE-2026-53566, along with patched client versions.
- NVD last-modifies both CVE-2026-53565 and CVE-2026-53566 records one day after publication; both remain in 'Awaiting Analysis' status with CWE-269 and CWE-125 respectively already assigned.
- TL-Intel Harness catalogs the disclosure as TL-2026-1474 based on CVSS 8.5 local privilege escalation affecting widely-deployed enterprise remote-access client software.
- Hungary's National Cybersecurity Institute (Nemzeti Kiberbiztonsagi Intezet / NKI) mirrors advisories for both CVE-2026-53565 and CVE-2026-53566, extending disclosure reach to national CSIRT consumers.
- CISA Known Exploited Vulnerabilities catalog reviewed; CVE-2026-53565 and CVE-2026-53566 are not listed, consistent with no confirmed active exploitation.
- Cyber Security News publishes coverage of the Citrix advisory, drawing wider attention to the privilege escalation and information disclosure issues.
Sources cited for Citrix Secure Access and Endpoint Analysis Client for
- Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows Security Bulletin for CVE-2026-53565 and CVE-2026-53566 (CTX696734)
- Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
- CVE-2026-53565 Security Vulnerability Analysis & Exploit Details
- CVE-2026-53566 – Nemzeti Kiberbiztonsági Intézet
- NVD CVE-2026-53565 Detail
- NVD CVE-2026-53566 Detail
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-1474
As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1474 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.