CVE-2016-5302: Citrix Xenserver

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.

Affected products

  • Citrix Xenserver: up to and including 7.0

Published 2016-06-13. Last modified 2026-06-17.