CVE-2018-10654: Citrix XenMobile Server

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

Affected products

  • Citrix XenMobile Server: version 10.8 only; version 10.7 only

Published 2018-05-23. Last modified 2026-06-17.