This is a historical alert, not a new 2026 patch notice: SecurityWeek reported on September 13, 2021, that Citrix had issued fixes for five Citrix Hypervisor vulnerabilities. Their potential effects varied: some could allow host compromise, while others could cause a denial of service. The report named hotfix target releases but did not provide hotfix IDs. Administrators should check Citrix’s current security bulletins for guidance that matches their installed release.
What the 2021 Citrix Hypervisor alert reported
SecurityWeek’s September 13, 2021 report identified five vulnerabilities: CVE-2021-28697, CVE-2021-28694, CVE-2021-28698, CVE-2021-28699, and CVE-2021-28701. The flaws involved interactions between guest virtual machines and the hypervisor, including grant-table permissions and memory handling. The reported impacts were not identical, so the headline’s reference to host compromise should not be read as the consequence of every CVE.
The report named three severity scores: CVE-2021-28697 at CVSS 7.8, CVE-2021-28694 at 6.8, and CVE-2021-28698 at 5.5. These are vulnerability severity scores reported by SecurityWeek in 2021, not counts of incidents or affected installations. Read SecurityWeek’s report.
How the five issues differed
- CVE-2021-28697: The most severe issue in the report, scored CVSS 7.8. A problem with a grant-table status page could leave a guest with access to pages after they had been freed and reused.
- CVE-2021-28694: Scored CVSS 6.8. The report linked it to ACPI memory mappings and the possibility of a host denial of service.
- CVE-2021-28698: Scored CVSS 5.5. Slow iteration over domain grant mappings could also cause a denial of service.
- CVE-2021-28699: The report said host compromise could result if an administrator had modified guest or host grant-table limits. It identified Citrix Hypervisor 8.2 LTSR as the affected release for this CVE.
- CVE-2021-28701: The report described a host-compromise risk in which the hypervisor reallocated pages while the guest retained permissions.
SecurityWeek reproduced a CISA statement saying that an attacker could exploit the vulnerabilities to take control of an affected system. That warning describes risk, not evidence that attacks or compromises had occurred. The report did not give an incident count or number of affected installations.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Which releases and hotfix targets the report named
SecurityWeek said the issues affected all then-currently supported Citrix Hypervisor versions, with CVE-2021-28699 limited to Citrix Hypervisor 8.2 LTSR. It reported hotfixes for Citrix Hypervisor 7.1 LTSR CU2 and 8.2 LTSR.
The report did not list hotfix identifiers or installation instructions. Do not infer a specific hotfix ID from the target release names. Confirm the relevant fix and installation route in Citrix guidance for the exact release and configuration you run.
Rank #2
What administrators should do now
For a system still running a release from the 2021 report, use the vendor’s current guidance rather than treating the old alert as a complete remediation plan. Citrix’s XenServer security bulletin index includes later updates through September 8, 2026, and advises applying published updates promptly. That index does not, by itself, establish whether the 2021 releases remain supported or define a supported upgrade path.
- Identify the installed product and release. Record the precise Citrix Hypervisor or XenServer version and update level.
- Check Citrix’s current security bulletins. Match the installed release to the bulletin and follow its applicability and remediation instructions. Open the XenServer security bulletin index.
- Verify the supported route before changing production hosts. Confirm with Citrix the applicable fix or upgrade path for your version, especially if you are on an older LTSR release.
- Apply the vendor-recommended update promptly. Follow the instructions for that release; the 2021 SecurityWeek report alone is not sufficient to identify a current package or installation procedure.
Keep this alert separate from Citrix’s 2020 advisory
Citrix advisory CTX284874 covers a different, 2020 set of six Hypervisor vulnerabilities. It is not the source for the five CVEs in the September 2021 report. See Citrix CTX284874.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

