CVE-2025-6759: Citrix Virtual Apps And Desktops

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

Affected products

  • Citrix Virtual Apps And Desktops: before 2503 (fixed in 2503); version 2402 only

Published 2025-07-08. Last modified 2026-06-17.