Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436) — Threadlinqs Intelligence
As of 2026-07-31, Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1781 · Severity: HIGH · CVSS: 7.8 · Status: ACTIVE · Category: VULNERABILITY
HKCERT and CERT-FR advisories cover seven CVEs in Citrix XenServer 8.4 and 9 (unpatched), all traced to underlying Xen Project hypervisor bugs (XSA-496, 500, 501, 504, 505, 507) in Xenstore
On 2026-07-28 the Xen Project disclosed six coordinated security advisories (XSA-496, XSA-500, XSA-501, XSA-504, XSA-505, XSA-507) covering seven CVEs that collectively affect Citrix XenServer 8.4 and XenServer 9, both of which ship the vulnerable Xen hypervisor components. Citrix shipped fixes the same day under Security Bulletin CTX696836; CERT-FR (CERTFR-2026-AVI-0941, 2026-07-29) and HKCERT (bulletin 2026-07-30, alert A26-07-53 2026-07-31) subsequently issued consolidated advisories.
CVE-2026-42492 (XSA-496, CVSS 7.5) is an incomplete-cleanup bug (CWE-459) in the binding of the VIRQ_DOM_EXC virtual IRQ used by Xenstore's XEN_DOMCTL_get_domain_state hypercall to track domain appearance/disappearance. An error path tears down the underlying bitmap even when it was never initialized, and an unprivileged domain can trigger this path, breaking Xenstore host-wide (DoS; theoretical hypervisor crash). Affects Xen 4.21 and later.
CVE-2026-62428 (XSA-500, CVSS 7.8, the highest-severity issue in this batch, CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H per NVD) is a time-of-check/time-of-use race (CWE-367) in grant-copy processing. Per the advisory: 'When grant-copy operations are processed, the respective grant may or may not already be in use by another operation. For all copy operations the referenced guest frame is looked up. When another operation is already active for the grant (the grant is "pinned"), what is being supplied back to actually carry out permission checks and copy operation may not be consistent: The permission check may be carried out on a page different from the one involved in the copy' — a type-confusion condition. An unprivileged guest can leverage this for information disclosure, DoS, or full privilege escalation to the host. Affects Xen 4.2 through unstable (excluding 4.1 and earlier, and builds without CONFIG_GRANT_TABLE / grant-table support).
CVE-2026-62431 (XSA-504, CVSS 7.5) is a divide-by-zero (CWE-369) in the periodic Viridian STIMER (synthetic timer) emulation path: the code performs a division using an unchecked, guest-controlled divisor that can be set to zero, triggering a #DE fault and host-wide DoS on HVM guests with Viridian STIMERs enabled (disabled by default). Affects Xen 4.13 and later.
CVE-2026-62432 (XSA-505, CVSS 7.3) is a race condition (CWE-362) between the EVTCHNOP_expand_array hypercall — which 'checks for whether FIFO event channels are enabled, but without holding the correct lock' — and EVTCHNOP_reset. By timing calls to both hypercalls, a guest can force expand_array to dereference memory that reset has already freed, causing a NULL-pointer dereference. HVM guests (x86 HVM, PVH, and Arm variants) can reliably trigger a host crash; for x86 PV guests memory corruption or privilege escalation cannot be ruled out. Affects Xen 4.5 and later.
CVE-2026-62434 (XSA-507, CVSS 5.3) lets a guest started with Populate-on-Demand (PoD, maxmem greater than memory in its xl config) attempt to reclaim special (non-regular-RAM) pages, corrupting Xen's memory-management state (CWE-787, out-of-bounds write); crashes/malfunctions are the primary risk, with information disclosure and privilege escalation not ruled out. Affects x86 HVM/PVH guests on Xen 3.4 and later.
CVE-2026-62435 and CVE-2026-62436 (both XSA-501, CVSS 6.5 each) are companion race conditions (CWE-362) in the grant-table v1<->v2 version-switch path. Code that drops and re-acquires the grant-table lock during the switch wrongly assumes certain properties cannot change during that unsynchronized window: CVE-2026-62435 covers the v1-to-v2 transition (switching to v2 reduces valid grant references, since the shared entry structure grows larger while table size stays constant); CVE-2026-62436 covers the v2-to-v1 transition (reverting to v1 eliminates status frames, which exist separately in v2). Both require x86 guests with grant-table v2 support and multiple vCPUs (Arm does not support grant-table v2), and can lead to guest-to-host p
Weaknesses (CWE)
CWE-459, CWE-367, CWE-369, CWE-362, CWE-787
Target sectors: government administration, financial services, health, technology, telecoms, cloud hosting, managed service providers, critical infrastructure
Target regions: Global, Asia-Pacific, Europe
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436, T1595.002, T1592.002, T1588.006, T1587.004, T1082, T1518, T1106, T1068, T1611, T1611