Vendor
Xen Project vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 42 vulnerabilities in Xen Project: 0 in the last 7 days and 23 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-62436, was published on 28 July 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 23
- Critical, all time
- 0
- Exploited in the wild
- 0
About Xen Project
An open-source project that develops the Xen hypervisor and related virtualization technologies.
Xen Project technologies
Latest Xen Project vulnerabilities
- CVE-2026-62436: Xen grant table race condition in version switchinginfoCVSS 0
- CVE-2026-62435: Xen grant table race condition in version switchinginfoCVSS 8.8
- CVE-2026-62434: Xen memory management state corruption in Populate on DemandinfoCVSS 0
- CVE-2026-62433: Xen DM_OP missing buffer validation in hypercallsinfoCVSS 0
- CVE-2026-62432: Xen race condition in FIFO event channel expansioninfoCVSS 0
- CVE-2026-62431: Xen Viridian STIMER division by zero denial of serviceinfoCVSS 6.8
- CVE-2026-62430: Xen x86 out-of-bounds read in vRTC emulationinfoCVSS 0
- CVE-2026-62429: Xen vNUMA race condition during domain destructioninfoCVSS 0
- CVE-2026-62428: Xen grant-table type confusion in grant-copyinfoCVSS 8.8
- CVE-2026-62427: Xen Project denial of service in platform-op locksinfoCVSS 0
- CVE-2026-62426: Xen Project Xen denial of service via unfair sysctl and platform-op locksinfoCVSS 0
- CVE-2026-62425: Xen libfsimage buffer overflow in Rock Ridge CE record processinginfoCVSS 8.8
- CVE-2026-62424: Xen libfsimage buffer overrun in Rock Ridge NM record processinginfoCVSS 0
- CVE-2026-62423: Xen libfsimage buffer overrun in Rock Ridge extension loopinfoCVSS 0
- CVE-2026-42495: Xen libfsimage integer underflow in iso9660 System Use area calculationinfoCVSS 8.8
- CVE-2026-42494: Xen libfsimage buffer overruns in iso9660 handlinginfoCVSS 0
- CVE-2026-42493: Xen Project Denial of Service in x86 shadow paginginfo
- CVE-2026-42492: Xen vIRQ event channel binding error in XenstoreinfoCVSS 6.5
- CVE-2026-23556: Xen Project oxenstored resource leak in domain teardowninfoCVSS 9.4
- CVE-2025-58151: Xen Project varstored TOCTOU in UEFI variable handlinginfoCVSS 9.4
- CVE-2025-27464: Xen Project Windows PV drivers privilege escalation in XenBusinfoCVSS 9.4
- CVE-2025-27463: Xen Project Windows PV drivers privilege escalation in XenIfaceinfoCVSS 9.4
- CVE-2025-27462: Xen Project Windows PV drivers incorrect default permissions in XenConsinfoCVSS 9.4
- CVE-2026-42490: Xen improper locking in domctl operationsmediumCVSS 6.5
- CVE-2026-42489: Xen Project Xen improper locking in domctl operationsmediumCVSS 5.3
Most severe Xen Project vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2016-9383: Xen broken bit test instruction emulation memory corruptionhighCVSS 8.8
- CVE-2026-42488: Xen x86 mapcache corruption in shadow paging error pathshighCVSS 8.1
- CVE-2026-42487: Xen x86 HVM race condition in I/O port list traversalhighCVSS 7.9
- CVE-2016-9379: Xen pygrub delimiter injection in S-expression outputhighCVSS 7.9
- CVE-2016-10013: Xen privilege escalation via SYSCALL singlestep emulationhighCVSS 7.8
- CVE-2016-9386: Xen x86 emulator privilege escalation via NULL segment handlinghighCVSS 7.8
- CVE-2016-9382: Xen x86 task switch privilege escalation in VM86 modehighCVSS 7.8
- CVE-2016-9381: Xen QEMU race condition in shared ring processinghighCVSS 7.5
- CVE-2016-9380: Xen pygrub arbitrary file read and deletion via delimiter injectionhighCVSS 7.5
- CVE-2025-54518: AMD Zen 2 Processors privilege escalation via CPU Opcode Cache corruptionhighCVSS 7EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 18 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/xen-project.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Xen Project vulnerabilities", https://junglewise.ai/threats/vendors/xen-project, 26 September 2026.