EIP-2026-115060

PRE-CVE

Citrix XenApp / XenDesktop XML Service - Heap Corruption

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115060. PoCs published by n.runs AG.

AI-analyzed exploit summary This advisory details a heap corruption vulnerability in Citrix XML Service (ctxxmls.exe) for XenApp and XenDesktop, triggered by sending a POST request with an excessively long non-existent extension DLL path. The issue leads to potential arbitrary code execution, though exploitation reliability was not confirmed.

Description

Citrix XenApp / XenDesktop XML Service - Heap Corruption

Exploits (1)

exploitdb WRITEUP VERIFIED
by n.runs AG · textdoswindows
https://www.exploit-db.com/exploits/17583

This advisory details a heap corruption vulnerability in Citrix XML Service (ctxxmls.exe) for XenApp and XenDesktop, triggered by sending a POST request with an excessively long non-existent extension DLL path. The issue leads to potential arbitrary code execution, though exploitation reliability was not confirmed.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Citrix XenApp and XenDesktop (XML Service)
No auth needed
Prerequisites: Network access to the XML service (default port 80)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026