Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Citrix Workspace App and Receiver for Windows Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in Citrix Workspace App and Citrix Receiver for Windows, prior to version 1904. This issue arises from incorrect access control, allowing local drive access preferences to be exploited. As a result, malicious code could potentially be executed remotely.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users are advised to update to Citrix Workspace App version 1904 or later. Instructions for updating can be found on the Citrix Support website.

Added: May 15, 2026, 10:22 AM
Updated: May 15, 2026, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
5.9
remediation
0.0
relevance
0.0
threat
8.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.