logo

Citrix Hypervisor vulnerabilities: How to find affected assets

ID: 18bf9fd0-7916-523a-a69e-492258c8333a

STIX ID: report--18bf9fd0-7916-523a-a69e-492258c8333a

Feed Name: runZero Blog

Threat Score
88/100

Date Published: 2024-09-25

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

Researchers disclosed 89 exploitable input-validation vulnerabilities across XAPI Map(String,String) fields in Citrix Hypervisor/XenServer and XCP-ng, allowing an authenticated vm-admin to gain host filesystem read/write, cross-VM data exfiltration, storage-protocol injection, cross-hypervisor lateral movement, and pool-wide compromise; the flaws affect all XAPI-based distributions (present since ~2006), carry a distribution of 5 critical/28 high/46 medium/10 low severities, have no CVE IDs yet, and researchers recommend full rebuilds since no vendor patches are currently available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.