Their weakest point is the hypervisor, Xen, which while a better choice than Linux/KVM, is still extremely bloated and has a poor security history.
Thankfully, better designs such as seL4's VMM do exist, although it might need a little more work [1] until usable for the purpose.
replies(6):