CVE-2018-18571 – Authentication Bypass vulnerability in XenMobile Server

Citrix recommends customers running Citrix XenMobile Server 10.9.0 upgrade to Rolling Patch 3 found at and Citrix XenMobile Server 10.8.0 upgrade to Rolling Patch 6 found at

Also, a newer version of Citrix XenMobile Server is now available: Citrix XenMobile Server version

Citrix strongly recommends that affected customers upgrade their XenMobile Servers to the new version. This new version can be obtained from the following location:

Citrix Product Downloads:

These issues have already been addressed in the Citrix Cloud service.

Windows device users who have upgraded to Citrix Endpoint Management 19.3.1, please reference the following article and recreate your Store device policy:


  • No Related Posts

Leave a Reply