โ† All reports

The xrdp RDP server versions up to 0.10.5 contain multiple vulnerabilities that could allow attackers to exploit the software, leading to potential security breaches.

CybersecurityApr 17, 2026score 0.278 posts ยท 0 replies across 2 instances
Multiple vulnerabilities were reported in the xrdp RDP server software, affecting versions up to 0.10.5. These vulnerabilities include issues like buffer overflows, privilege escalation, and remote code execution, which could allow attackers to exploit the software. The vulnerabilities highlight security risks in the software's handling of RDP packets and session management.

Claims

The xrdp RDP server versions up to 0.10.5 contain multiple vulnerabilities that could allow attackers to exploit the software, leading to potential security breaches.
Parent: CybersecurityEntity: xrdp RDP ServerImpact: negativeDate: Apr 17, 2026Target: Security of xrdp RDP server versions up to 0.10.5

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23474 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate pr... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23474 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23472 ๐Ÿ“Š Score: 9.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly generat... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23472 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23504 ๐Ÿ“Š Score: 7.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from xrdp to another server, the module fails to properly validate the size of reassembled f... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23504 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23515 ๐Ÿ“Š Score: 7.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when memory is accessed before validating the remaining buffer length. A remote, unauthenticat... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23515 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23506 ๐Ÿ“Š Score: 6.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated remote attacker can send a craf... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23506 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23510 ๐Ÿ“Š Score: 6.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrdp-sesman. When the AllowAlternateShell setting is enabled... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23510 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23516 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence of pac... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23516 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23519 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: xrdp ๐Ÿข Vendor: neutrinolabs ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23519 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability