Citrix Workspace app for Windows Security Bulletin CVE-2026-78546 and CVE-2026-78547
Description of Problem
Two vulnerabilities have been discovered that impact the Citrix Workspace app for Windows.
Affected Versions
The vulnerabilities affect the following supported versions of the Citrix Workspace app for Windows.
Current Release (CR)
- Citrix Workspace app for Windows versions BEFORE 2603.11
Long Term Service Release (LTSR)
- Citrix Workspace app for Windows versions BEFORE 2507.1 LTSR CU3
- Citrix Workspace app for Windows versions BEFORE 2607 LTSR
Summary
CVE-ID | Description | Pre-conditions | CWE | CVSSv4 |
| CVE-2026-78546 | Out-of-Bounds Read | Local access to the target system | CWE-125: Out-of-bounds Read | CVSS v4.0 Base Score: 4.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N) |
| CVE-2026-78547 | Out-of-Bounds Write | Physical access to the target system | CWE-787: Out-of-bounds Write | CVSS v4.0 Base Score: 4.4 (CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC |
What Customers Should Do
Citrix strongly recommends that customers upgrade their Citrix Workspace app for Windows to versions that contain the fixes as soon as possible.
Citrix Workspace app for Windows versions that contain the fixes are:
Current Release (CR)
- Citrix Workspace app for Windows 2603.11 and later versions
Long Term Service Release (LTSR)
- Citrix Workspace app for Windows 2507.1 LTSR CU3 and later versions
- Citrix Workspace app for Windows 2607 LTSR