VORANT. Threat Intelligence Sign in Get the full feed

Citrix XenServer patches multiple vulnerabilities

medium vulnerability

CERT-FR advisory details multiple Citrix XenServer flaws allowing remote code execution and denial of service, patched via CTX696836.

CERT-FR issued an advisory covering multiple vulnerabilities in Citrix XenServer versions 8.4 and 9 that lack the latest security patch. The flaws, tracked under seven CVEs, allow attackers to achieve remote arbitrary code execution, remote denial of service, and an unspecified security impact not detailed by the vendor.

Citrix addressed the issues in security bulletin CTX696836, published 28 July 2026. No active exploitation is reported; the advisory is a standard vulnerability disclosure and patch notice. Affected organizations should apply the vendor's correctifs as soon as possible to remediate the RCE and DoS conditions.

Mentioned in this report

Vulnerabilities CVE-2026-42492CVE-2026-62428CVE-2026-62431CVE-2026-62432CVE-2026-62434CVE-2026-62435CVE-2026-62436

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0941

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free