Threat reportVulnerabilityTL-2026-1474

Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)

highPATCHED

Citrix Secure Access and Endpoint Analysis Client for (TL-2026-1474) is a high-severity software vulnerability scored CVSS 8.5, first published 2026-07-18. It has no confirmed attribution, affects Cloud Software Group / Citrix Citrix Secure Access Client for Windows, references 2 CVEs (CVE-2026-53565, CVE-2026-53566), maps to 16 MITRE ATT&CK techniques (T1003, T1005, T1059), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
8.5/10High
CVEs
2Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-1474

Threat ID
TL-2026-1474
Severity
HIGH
CVSS
8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
enterprise, government administration, finance, health, technology, remote-workforce
Target regions
Global
Detection rules
9
Indicators of compromise
16

How Citrix Secure Access and Endpoint Analysis Client for works

Citrix disclosed two local vulnerabilities affecting its Secure Access Client and Endpoint Analysis Client for Windows: CVE-2026-53565, an improper privilege management flaw (CVSS 4.0 8.5) that lets a standard local user escalate to SYSTEM, and CVE-2026-53566, an out-of-bounds memory read (CVSS 4.0 6.8) that discloses sensitive information when the DNE driver is not installed. No public PoC or active exploitation has been confirmed; patches are available.

On July 14, 2026, Cloud Software Group (Citrix) published security bulletin CTX696734 disclosing two local vulnerabilities in Windows client software used for remote-access VPN and endpoint compliance scanning: Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.

CVE-2026-53565 (CWE-269, Improper Privilege Management, CVSS 4.0 base score 8.5, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) affects both clients. A low-privileged local user who already has standard, non-administrative access to the endpoint can abuse a flaw in how the client software manages privileged operations — typical root causes for this class of bug in VPN/endpoint-agent Windows services include an insecure named pipe or IPC channel exposed by a SYSTEM-level service, a privileged helper process that trusts unvalidated input from a lower-integrity client process, or a misconfigured service/driver ACL that allows a standard user to trigger privileged code paths — to escalate local privileges to SYSTEM. Because the affected software runs as a background Windows service/driver stack that is installed with elevated privileges on endpoints across the enterprise (a common deployment pattern for VPN/ZTNA and endpoint-compliance agents), successful exploitation gives an attacker who already has a low-privileged foothold (e.g., via phishing, a compromised user session, or a supply-chain-delivered implant) full SYSTEM-level control of the host — enabling credential dumping, security-tooling tampering, persistence installation, and lateral movement.

CVE-2026-53566 (CWE-125, Out-of-bounds Read, CVSS 4.0 base score 6.8, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N) affects the Citrix Secure Access Client for Windows. It is an out-of-bounds memory read that a standard local user can trigger to disclose sensitive in-memory data (a common consequence class includes leaked pointers, credentials, or other process memory contents that can be leveraged to defeat memory-protection mitigations or as a stepping stone toward further exploitation). Citrix documents this vulnerability's impact as conditional on the DNE (Device/Deterministic Network Enhancer, referred to by Citrix documentation as the DNE driver component bundled with the Secure Access networking stack) driver not being installed on the endpoint; administrators can check DNE driver presence via NetScaler Gateway/Secure Access client configuration documentation.

Both vulnerabilities require only local, standard-user access with no user interaction (UI:N) and low attack complexity (AC:L), making them attractive as a second-stage privilege-escalation primitive following any form of initial access that grants a foothold as a non-administrative user — a very common outcome of phishing, malicious document execution, or compromised low-privilege service accounts.

Citrix credits Carlos Garrido of Pentraze Cybersecurity with discovering and responsibly disclosing both issues. As of this writing there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation; the CVEs do not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Citrix has shipped fixed builds for both affected clients, and remediation is a straightforward client update — no workaround is documented as a substitute for patching the privilege-escalation issue (CVE-2026-53565), while DNE driver installation is noted as a relevant configuration factor for CVE-2026-53566 exposure.

MITRE ATT&CK techniques used in TL-2026-1474

Credential Access

T1003 OS Credential Dumping; T1212 Exploitation for Credential Access

Collection

T1005 Data from Local System

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism

Discovery

T1082 System Information Discovery; T1518 Software Discovery

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1489 Service Stop

Persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Initial Access

T1566 Phishing

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Citrix Secure Access and Endpoint Analysis Client for

  • Cloud Software Group / Citrix — Citrix Secure Access Client for Windows
    Vulnerable versions: versions before 26.6.1.20
    Fixed in: 26.6.1.20 and later
  • Cloud Software Group / Citrix — Citrix Endpoint Analysis Client for Windows
    Vulnerable versions: versions before 26.5.1.7 (CVE-2026-53565 only)
    Fixed in: 26.5.1.7 and later

Remediation for Citrix Secure Access and Endpoint Analysis Client for

Patches

  • Citrix Secure Access Client for Windows 26.6.1.20 (CTX696734)
  • Citrix Endpoint Analysis Client for Windows 26.5.1.7 (CTX696734)

Immediate actions

  • Upgrade Citrix Secure Access Client for Windows to version 26.6.1.20 or later
  • Upgrade Citrix Endpoint Analysis Client for Windows to version 26.5.1.7 or later
  • Inventory all Windows endpoints running Citrix Secure Access Client or Citrix Endpoint Analysis Client to identify unpatched versions
  • Verify whether the DNE driver is installed on Secure Access Client endpoints to assess exposure to CVE-2026-53566

Workarounds

  • No effective workaround beyond patching is documented for CVE-2026-53565
  • Removing or not installing the DNE driver component is a documented condition affecting CVE-2026-53566 exposure, per Citrix guidance

Longer-term hardening

  • Enforce least-privilege on endpoints so a compromised standard-user session cannot be trivially used as a springboard for local privilege escalation
  • Deploy EDR/endpoint monitoring for anomalous SYSTEM-level process spawning from Citrix client service accounts
  • Establish a recurring patch-management cadence specifically for VPN/ZTNA and endpoint-compliance client software given their elevated-privilege footprint
  • Monitor Citrix security bulletins (support.citrix.com) for follow-on advisories affecting Secure Access and Endpoint Analysis clients

CVEs associated with Citrix Secure Access and Endpoint Analysis Client for

CVE-2026-53565, CVE-2026-53566

Weaknesses (CWE) in Citrix Secure Access and Endpoint Analysis Client for

CWE-269, CWE-125

Timeline of Citrix Secure Access and Endpoint Analysis Client for

  • Carlos Garrido of Pentraze Cybersecurity reports the improper privilege management and out-of-bounds read issues to Cloud Software Group / Citrix under responsible disclosure (exact private-disclosure date not published by vendor; placed prior to public bulletin).
  • Citrix Secure Access Client for Windows 26.6.1.20 and Citrix Endpoint Analysis Client for Windows 26.5.1.7 are made available to remediate the vulnerabilities.
  • Cloud Software Group publishes security bulletin CTX696734 disclosing CVE-2026-53565 and CVE-2026-53566, along with patched client versions.
  • NVD last-modifies both CVE-2026-53565 and CVE-2026-53566 records one day after publication; both remain in 'Awaiting Analysis' status with CWE-269 and CWE-125 respectively already assigned.
  • TL-Intel Harness catalogs the disclosure as TL-2026-1474 based on CVSS 8.5 local privilege escalation affecting widely-deployed enterprise remote-access client software.
  • Hungary's National Cybersecurity Institute (Nemzeti Kiberbiztonsagi Intezet / NKI) mirrors advisories for both CVE-2026-53565 and CVE-2026-53566, extending disclosure reach to national CSIRT consumers.
  • CISA Known Exploited Vulnerabilities catalog reviewed; CVE-2026-53565 and CVE-2026-53566 are not listed, consistent with no confirmed active exploitation.
  • Cyber Security News publishes coverage of the Citrix advisory, drawing wider attention to the privilege escalation and information disclosure issues.

Sources cited for Citrix Secure Access and Endpoint Analysis Client for

Detection coverage for TL-2026-1474

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1474 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats