CVE-2026-78546
Received Received - Intake

Out-of-Bounds Read in Citrix Workspace Windows App

Vulnerability report for CVE-2026-78546, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Citrix Systems, Inc.

Description

Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
citrix workspace_app to 2603.11 (exc)
citrix workspace_app to 2507.1 (exc)
citrix workspace_app to 2607 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in the Citrix Workspace app for Windows. It allows an attacker with local access to read memory outside the intended buffer, potentially exposing sensitive data.

Impact Analysis

An attacker could exploit this to access sensitive information on your system, such as passwords or other confidential data. It requires local access but could lead to further compromise if combined with other vulnerabilities.

Mitigation Strategies

Update Citrix Workspace app for Windows to version 2603.11 Current Release (CR), 2507.1 LTSR CU3, or LTSR 2607 to address the out-of-bounds read vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78546. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart