Citrix has fixed multiple vulnerabilities within their XenMobile Server product. XenMobile is software used to manage (mobile) devices and applications and is also known as Citrix Endpoint Management (CEM). The vulnerabilities allow hackers to remotely access sensitive data and execute code with administrator (root) privileges. The vulnerabilities are known under the following headings (CVE-2020-8208, CVE-2020-8209, CVE-2020-8210, CVE-2020-8211, CVE-2020-8212).

Citrix recommends installing the available security updates as soon as possible because they are expected to be exploited in the near future.
The NCSC also designates the vulnerabilities as HIGH/HIGH, meaning that both the likelihood of misuse and its potential impact are high.
Citrix provides more information about the vulnerability and which versions of XenMobile are vulnerable on this page. You will also find download links for available security updates.
CVE-2020-8208
CVE-2020-8209
CGU-2020-8210
CGU-2020-8211
CVE-2020-8212
