Out-of-bounds read in Secure Access Client for Windows - CVE-2026-53566

 

Out-of-bounds read in Secure Access Client for Windows - CVE-2026-53566

Published: July 15, 2026


Vulnerability identifier: #VU137690
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53566
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Citrix Secure Access Client for Windows when processing memory on a local system. A local user can trigger the out-of-bounds read to disclose sensitive information.

Exploitation requires standard user access on the local system, and the DNE driver must not be installed.


Affected software

Secure Access Client for Windows

How to mitigate CVE-2026-53566

Install security update from vendor's website.

Secure Access Client for Windows - update to 26.6.1.20

External References

Related Security Bulletins