Technology · Citrix
Citrix XenServer vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 11 vulnerabilities in Citrix XenServer: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2017-5573, was published on 30 January 2017.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About Citrix XenServer
A virtualization platform based on the Xen Project hypervisor for managing cloud and server workloads.
Latest Citrix XenServer vulnerabilities
- CVE-2017-5573: Citrix XenServer authorization bypass in xapimediumCVSS 4.9
- CVE-2017-5572: Citrix XenServer database corruption via xapi privilege escalationmediumCVSS 6.5
- CVE-2016-10025: Xen VMFUNC emulation NULL pointer dereference on AMD SVMmediumCVSS 5.5
- CVE-2016-10024: Xen denial of service via instruction stream modification in x86 PV guestsmediumCVSS 6
- CVE-2016-9386: Xen x86 emulator privilege escalation via NULL segment handlinghighCVSS 7.8
- CVE-2016-9385: Xen x86 segment base write emulation denial of servicemediumCVSS 6
- CVE-2016-9383: Xen broken bit test instruction emulation memory corruptionhighCVSS 8.8
- CVE-2016-9382: Xen x86 task switch privilege escalation in VM86 modehighCVSS 7.8
- CVE-2016-9381: Xen QEMU race condition in shared ring processinghighCVSS 7.5
- CVE-2016-9380: Xen pygrub arbitrary file read and deletion via delimiter injectionhighCVSS 7.5
- CVE-2016-9379: Xen pygrub delimiter injection in S-expression outputhighCVSS 7.9
Most severe Citrix XenServer vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2016-9383: Xen broken bit test instruction emulation memory corruptionhighCVSS 8.8
- CVE-2016-9379: Xen pygrub delimiter injection in S-expression outputhighCVSS 7.9
- CVE-2016-9386: Xen x86 emulator privilege escalation via NULL segment handlinghighCVSS 7.8
- CVE-2016-9382: Xen x86 task switch privilege escalation in VM86 modehighCVSS 7.8
- CVE-2016-9381: Xen QEMU race condition in shared ring processinghighCVSS 7.5
- CVE-2016-9380: Xen pygrub arbitrary file read and deletion via delimiter injectionhighCVSS 7.5
- CVE-2017-5572: Citrix XenServer database corruption via xapi privilege escalationmediumCVSS 6.5
- CVE-2016-10024: Xen denial of service via instruction stream modification in x86 PV guestsmediumCVSS 6
- CVE-2016-9385: Xen x86 segment base write emulation denial of servicemediumCVSS 6
- CVE-2016-10025: Xen VMFUNC emulation NULL pointer dereference on AMD SVMmediumCVSS 5.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/xenserver.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Citrix XenServer vulnerabilities", https://junglewise.ai/threats/technologies/xenserver, 26 September 2026.