logo

The Shittrix Disclosure: 89 Flaws Collapse 20 Years of Trust in Citrix and XCP-ng

ID: 4c8f4cb5-e9ca-5af7-a6ff-b6eb3067b24f

STIX ID: report--4c8f4cb5-e9ca-5af7-a6ff-b6eb3067b24f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Ddos

...
...

Independent researcher Jakob Wolffhechel disclosed 89 vulnerabilities in Citrix XenServer/Hypervisor and XCP-ng (dubbed “Shittrix”), describing pervasive input-validation failures since ~2006 that let minimally privileged management users execute single API calls to gain full host filesystem access, mount any host block device, proxy malformed storage-protocol commands, exfiltrate cross-VM data, and potentially install persistent bootkits; key issues (e.g., BOC-1, SMC-1) are rated CVSS 9.9 and the researcher recommends treating any production host exposed during the 20-year window as compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.