CVE-2018-10648: Citrix XenMobile Server

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

Affected products

  • Citrix XenMobile Server: version 10.8 only; version 10.7 only

Published 2018-05-23. Last modified 2026-06-17.