Multiple Vulnerabilities in Xen (July 29, 2026)
Multiple vulnerabilities have been discovered in Xen. Some of them allow an attacker to cause privilege escalation, remote denial of service, and data confidentiality breaches.
CSIRTS triage
- What
- Multiple vulnerabilities allow privilege escalation, remote denial of service, and data confidentiality breaches.
- Who is affected
- Deployments of Xen are affected.
- Urgency
- Remediation is urgent due to the severity of the vulnerabilities.
- Action
- Apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Xen
Get an email when a new Xen advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0942/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-624290.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-624230.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-424920.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-424950.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-624270.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-624240.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-624260.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-624280.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-624360.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-424930.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Xen: Multiple vulnerabilitiescert-bund
- unknownXen Multiple Vulnerabilitieshkcert
- unknownCitrix XenServer Multiple Vulnerabilitieshkcert
- unknownMultiple Vulnerabilities in Citrix XenServer (July 29, 2026)cert-fr-avis
- mediumCVE-2026-62436: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnera…nvd
- mediumCVE-2026-62435: [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnera…nvd
- mediumCVE-2026-62434: A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren…nvd
- highCVE-2026-62433: Parts of the DM_OP handling code assumes the caller has provided the required number of buffer…nvd
- highCVE-2026-62432: The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but wi…nvd
- highCVE-2026-62431: The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-contr…nvd
- highCVE-2026-62430: Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen ne…nvd
- mediumCVE-2026-62429: Accessing the vNUMA configuration data of a guest is still possible when domain destruction ha…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31