Changeflow GovPing Data Privacy & Cybersecurity Citrix XenServer Vulnerability Allows Security ...
Priority review Notice Added Final

Citrix XenServer Vulnerability Allows Security Policy Bypass

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 18th, 2026
Detected March 18th, 2026
Email

Summary

CERT-FR has issued an advisory regarding a vulnerability in Citrix XenServer (CVE-2026-23554) that allows for security policy bypass. The advisory urges users to apply security patches provided by Citrix to affected systems.

What changed

CERT-FR has released an advisory (CERTFR-2026-AVI-0311) detailing a critical vulnerability, CVE-2026-23554, discovered in Citrix XenServer versions prior to the application of the latest security patches. This vulnerability allows an attacker to bypass the system's security policy, potentially leading to unauthorized access or actions. The advisory references Citrix's security bulletin CTX696350 for detailed information.

Organizations utilizing vulnerable versions of Citrix XenServer must immediately consult Citrix's security bulletin and apply the necessary patches to mitigate the risk of security policy bypass. Failure to do so could expose sensitive systems and data to compromise. While no specific compliance deadline is stated, prompt patching is essential for maintaining security posture.

What to do next

  1. Consult Citrix security bulletin CTX696350
  2. Apply security patches to affected XenServer installations

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 18 mars 2026 N° CERTFR-2026-AVI-0311 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Vulnérabilité dans Citrix XenServer

Gestion du document

| Référence | CERTFR-2026-AVI-0311 |
| Titre | Vulnérabilité dans Citrix XenServer |
| Date de la première version | 18 mars 2026 |
| Date de la dernière version | 18 mars 2026 |
| Source(s) | Bulletin de sécurité Citrix CTX696350 du 17 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risque

  • Contournement de la politique de sécurité

Systèmes affectés

  • XenServer 8.4 sans les derniers correctifs de sécurité

Résumé

Une vulnérabilité a été découverte dans Citrix XenServer. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 18 mars 2026 Version initiale

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 18th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Technology companies
Geographic scope
National (France)

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Network Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.