Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Citrix Workspace App and Receiver for Windows Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in Citrix Workspace App and Citrix Receiver for Windows, prior to version 1904. This issue arises from incorrect access control, allowing local drive access preferences to be exploited. As a result, malicious code could potentially be executed remotely.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users are advised to update to Citrix Workspace App version 1904 or later. Instructions for updating can be found on the Citrix Support website.

Added: May 15, 2026, 10:22 AM
Updated: May 15, 2026, 10:22 AM