news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans les produits Citrix (15 juillet 2026)

Medium
Summary

Multiple vulnerabilities have been discovered in Citrix products, including potential elevation of privileges, data compromise, and policy bypass. These vulnerabilities affect various Citrix components, requiring immediate patching to mitigate risks.

Multiple vulnerabilities have been discovered within Citrix products. These vulnerabilities could allow an attacker to elevate privileges, compromise data confidentiality, and circumvent security policies.

Systems affected include:

  • Endpoint Analysis Client versions prior to 26.5.1.7 for Windows
  • Secure Access Client versions prior to 26.6.1.20 for Windows
  • XenCenter SDK client versions prior to 26.15.0 for PowerShell and C#
  • XenCenter versions prior to 2026.4.0

The CERT-FR has linked to the following security bulletins for more details:

  • Citrix Security Bulletin CTX696734 (July 14, 2026) - https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696734&articleURL=Citrix_Secure_Access_Client_for_Windows_and_Citrix_Endpoint_Analysis_Client_for_Windows_Security_Bulletin_for_CVE_2026_53565_and_CVE_2026_53566
  • Citrix Security Bulletin CTX696811 (July 14, 2026) - https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696811&articleURL=XenServer_Security_Update_for_CVE_2026_42491

CVE identifiers are:

  • CVE-2026-42491
  • CVE-2026-53565
  • CVE-2026-53566
Read the full article at CERT-FR