Bg ShapeBg Shape
THREAT INTELLIGENCE

Citrix releases Security Bulletin for Workspace App

Affected Environment
Citrix Workspace app for Windows, versions before 2603.11, 2507.1 LTSR CU3, and 2607 LTSR.

Threat Overview
Two vulnerabilities allow local or physical access attackers to trigger out-of-bounds read and write conditions.

Exposure Timeline
Published 8 September 2026, with fixed Workspace app versions already available for all affected branches.

Attack Surface
Local or physical access to systems running Citrix Workspace app for Windows, no network exposure required.

Technical Root Cause
An out-of-bounds read and a separate out-of-bounds write both stem from insufficient memory boundary checks.

Exploitation Pathway
Attacker with local or physical device access reads or writes beyond intended memory boundaries within the app.

Operational Impact
Exploitation may disclose limited application memory contents or affect application integrity and availability.

Strategic Impact
Medium risk overall given the local and physical access preconditions limiting remote exploitation potential.

Required Mitigation
Upgrade Citrix Workspace app for Windows to the fixed versions listed for each release branch.

Incident Response Guidance
Restrict physical and local access to endpoints, and apply role-based access control reviews annually.

References
Citrix Support Knowledge Base article CTX697034.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image