# Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)

> Citrix disclosed two local vulnerabilities affecting its Secure Access Client and Endpoint Analysis Client for Windows: CVE-2026-53565, an improper privilege management flaw (CVSS 4.0 8.5) that lets a standard local user escalate to SYSTEM, and CVE-2026-53566, an out-of-bounds memory read (CVSS 4.0 6.8) that discloses sensitive information when the DNE driver is not installed. No public PoC or active exploitation has been confirmed; patches are available.

- **Published:** 2026-07-18T00:00:00Z
- **Last reviewed:** 2026-07-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1474
- **ID:** TL-2026-1474
- **Severity:** HIGH (CVSS 8.5)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-53565, CVE-2026-53566

## Description

On July 14, 2026, Cloud Software Group (Citrix) published security bulletin CTX696734 disclosing two local vulnerabilities in Windows client software used for remote-access VPN and endpoint compliance scanning: Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows.

CVE-2026-53565 (CWE-269, Improper Privilege Management, CVSS 4.0 base score 8.5, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) affects both clients. A low-privileged local user who already has standard, non-administrative access to the endpoint can abuse a flaw in how the client software manages privileged operations — typical root causes for this class of bug in VPN/endpoint-agent Windows services include an insecure named pipe or IPC channel exposed by a SYSTEM-level service, a privileged helper process that trusts unvalidated input from a lower-integrity client process, or a misconfigured service/driver ACL that allows a standard user to trigger privileged code paths — to escalate local privileges to SYSTEM. Because the affected software runs as a background Windows service/driver stack that is installed with elevated privileges on endpoints across the enterprise (a common deployment pattern for VPN/ZTNA and endpoint-compliance agents), successful exploitation gives an attacker who already has a low-privileged foothold (e.g., via phishing, a compromised user session, or a supply-chain-delivered implant) full SYSTEM-level control of the host — enabling credential dumping, security-tooling tampering, persistence installation, and lateral movement.

CVE-2026-53566 (CWE-125, Out-of-bounds Read, CVSS 4.0 base score 6.8, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N) affects the Citrix Secure Access Client for Windows. It is an out-of-bounds memory read that a standard local user can trigger to disclose sensitive in-memory data (a common consequence class includes leaked pointers, credentials, or other process memory contents that can be leveraged to defeat memory-protection mitigations or as a stepping stone toward further exploitation). Citrix documents this vulnerability's impact as conditional on the DNE (Device/Deterministic Network Enhancer, referred to by Citrix documentation as the DNE driver component bundled with the Secure Access networking stack) driver not being installed on the endpoint; administrators can check DNE driver presence via NetScaler Gateway/Secure Access client configuration documentation.

Both vulnerabilities require only local, standard-user access with no user interaction (UI:N) and low attack complexity (AC:L), making them attractive as a second-stage privilege-escalation primitive following any form of initial access that grants a foothold as a non-administrative user — a very common outcome of phishing, malicious document execution, or compromised low-privilege service accounts.

Citrix credits Carlos Garrido of Pentraze Cybersecurity with discovering and responsibly disclosing both issues. As of this writing there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation; the CVEs do not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Citrix has shipped fixed builds for both affected clients, and remediation is a straightforward client update — no workaround is documented as a substitute for patching the privilege-escalation issue (CVE-2026-53565), while DNE driver installation is noted as a relevant configuration factor for CVE-2026-53566 exposure.

## MITRE ATT&CK

- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1211 Exploitation for Stealth
- T1003 OS Credential Dumping
- T1212 Exploitation for Credential Access
- T1082 System Information Discovery
- T1518 Software Discovery
- T1005 Data from Local System
- T1489 Service Stop
- T1543 Create or Modify System Process
- T1685 Disable or Modify Tools
- T1566 Phishing
- T1078 Valid Accounts
- T1547 Boot or Logon Autostart Execution
- T1134 Access Token Manipulation
- T1059 Command and Scripting Interpreter

## Sources

- [Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows Security Bulletin for CVE-2026-53565 and CVE-2026-53566 (CTX696734)](https://support.citrix.com/external/article/CTX696734/citrix-secure-access-client-for-windows.html)
- [Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation](https://cybersecuritynews.com/citrix-secure-access-and-endpoint-vulnerability/)
- [CVE-2026-53565 Security Vulnerability Analysis & Exploit Details](https://cve.akaoma.com/cve-2026-53565)
- [CVE-2026-53566 – Nemzeti Kiberbiztonsági Intézet](https://nki.gov.hu/figyelmeztetesek/serulekenysegek/cve-2026-53566/)
- [NVD CVE-2026-53565 Detail](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-53565)
- [NVD CVE-2026-53566 Detail](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-53566)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1474
