CVE Tools

Description

Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.

In plain language

AI Act now

CVE-2026-78546 is a Windows software flaw in Citrix Workspace app where an attacker may be able to read data from the wrong memory area; most small businesses should patch because it’s reachable by default in older versions.

Executive summary

CVE-2026-78546 is an out-of-bounds read (CWE-125) in Citrix Workspace app for Windows where application logic/input processing can cause the client to access unauthorized memory locations; older client versions are reachable by default (fixed in Workspace app for Windows 2603.11 CR, 2507.1 LTSR CU3, and LTSR 2607).

If affected, business impact
Unauthorized access to sensitive dataPotential credential or session data exposureAccount takeover riskSecurity incident and downtime risk

What to do now

  1. Check your installed Citrix Workspace app for Windows version.
  2. If your version is older than 2603.11 CR, 2507.1 LTSR CU3, or LTSR 2607, plan an upgrade to the first fixed release you can deploy.
  3. Verify the upgrade completes successfully on all devices that use Citrix Workspace app for Windows.
  4. After updating, monitor for unusual client crashes, repeated connection attempts, or unexpected authentication/session behavior.
Usually a quick update

Weaknesses

Affected Products

Citirx
commercialaka citrix adc and citrix gateway, citrix adc, citrix gateway, citrix sd-wan

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-78546 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows