Known vulnerabilities in Citrix XenServer

Vendor: Citrix
Software CPE: cpe:2.3:a:citrix:citrix_xenserver:*:*:*:*:*:*:*:*
Total vulnerabilities: 45
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Citrix XenServer Citrix XenServer is affected by 45 known vulnerabilities: 1 high, 16 medium, 28 low Critical High Medium Low

Vulnerabilities (45)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140023 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-62435
CWE-362 Low
No
No
- 29.07.2026 SB2026072966
SB2026073102
SB2026073108
and 3 more
#VU140024 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-62436
CWE-362 Low
No
No
- 29.07.2026 SB2026072966
SB2026073102
SB2026073108
and 3 more
#VU140019 - Improper Initialization
CVE-2026-42492
CWE-665 Low
No
No
- 29.07.2026 SB2026072966
SB2026073102
SB2026073108
and 2 more
#VU140018 - Type confusion
CVE-2026-62428
CWE-843 Low
No
No
- 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140016 - Divide By Zero
CVE-2026-62431
CWE-369 Low
No
No
- 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 6 more
#VU140015 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-62432
CWE-362 Low
No
No
- 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU140014 - Out-of-bounds write
CVE-2026-62434
CWE-787 Low
No
No
- 29.07.2026 SB2026072966
SB2026073008
SB2026073052
and 7 more
#VU137514 - Improper Certificate Validation
CVE-2026-42491
CWE-295 Medium
No
No
2026.4.0 14.07.2026 SB2026071486
SB2026080209
#VU131218 - Improper Privilege Management
CVE-2025-54518
CWE-269 Low
No
No
- 12.05.2026 SB20260512104
SB2026051316
SB2026051320
and 87 more
#VU128446 - Improper Access Control
CVE-2026-23559
CWE-284 Medium
No
No
- 29.04.2026 SB2026042913
SB2026043082
#VU128447 - Improper Access Control
CVE-2026-23560
CWE-284 Low
No
No
- 29.04.2026 SB2026042913
SB2026043082
#VU128448 - Improper Access Control
CVE-2026-23561
CWE-284 Low
No
No
- 29.04.2026 SB2026042913
SB2026043082
#VU128449 - Improper Access Control
CVE-2026-23562
CWE-284 Low
No
No
- 29.04.2026 SB2026042913
SB2026043083
#VU128450 - Improper Access Control
CVE-2026-42486
CWE-284 Low
No
No
- 29.04.2026 SB2026042913
SB2026043083
#VU128379 - Missing Release of Resource after Effective Lifetime
CVE-2026-23556
CWE-772 Low
No
No
- 28.04.2026 SB20260428207
SB2026042901
SB20260429105
and 3 more
#VU128376 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-23558
CWE-362 Medium
No
No
- 28.04.2026 SB20260428207
SB20260428235
SB2026042901
and 10 more
#VU126567 - Observable discrepancy
CVE-2025-54505
CWE-203 Low
No
No
- 20.04.2026 SB2026042081
SB20260428235
SB2026042901
and 39 more
#VU124487 - Resource Management Errors
CVE-2026-4397
CWE-399 Low
No
No
- 25.03.2026 SB2026032590
#VU124113 - Use After Free
CVE-2026-23554
CWE-416 Medium
No
No
- 18.03.2026 SB2026031846
SB2026031847
SB2026031848
and 7 more
#VU122072 - Permissions, Privileges, and Access Controls
CVE-2026-23553
CWE-264 Low
No
No
- 27.01.2026 SB2026012780
SB2026012786
SB2026012838
and 8 more


Showing elements 1 - 20 out of 45