Description
Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
In plain language
AI Act nowCVE-2026-78546 is a Windows software flaw in Citrix Workspace app where an attacker may be able to read data from the wrong memory area; most small businesses should patch because it’s reachable by default in older versions.
CVE-2026-78546 is an out-of-bounds read (CWE-125) in Citrix Workspace app for Windows where application logic/input processing can cause the client to access unauthorized memory locations; older client versions are reachable by default (fixed in Workspace app for Windows 2603.11 CR, 2507.1 LTSR CU3, and LTSR 2607).
What to do now
- Check your installed Citrix Workspace app for Windows version.
- If your version is older than 2603.11 CR, 2507.1 LTSR CU3, or LTSR 2607, plan an upgrade to the first fixed release you can deploy.
- Verify the upgrade completes successfully on all devices that use Citrix Workspace app for Windows.
- After updating, monitor for unusual client crashes, repeated connection attempts, or unexpected authentication/session behavior.
Weaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-78546 and every CVE in our database. Create a free account — no credit card required.
Create Free Account