EIP-2026-115060
PRE-CVECitrix XenApp / XenDesktop XML Service - Heap Corruption
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-115060. PoCs published by n.runs AG.
AI-analyzed exploit summary This advisory details a heap corruption vulnerability in Citrix XML Service (ctxxmls.exe) for XenApp and XenDesktop, triggered by sending a POST request with an excessively long non-existent extension DLL path. The issue leads to potential arbitrary code execution, though exploitation reliability was not confirmed.
Description
Citrix XenApp / XenDesktop XML Service - Heap Corruption
Exploits (1)
This advisory details a heap corruption vulnerability in Citrix XML Service (ctxxmls.exe) for XenApp and XenDesktop, triggered by sending a POST request with an excessively long non-existent extension DLL path. The issue leads to potential arbitrary code execution, though exploitation reliability was not confirmed.