CVE Tools

Xrdp

40 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Xrdp, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Xrdp CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Xrdp CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-020
2026-030
2026-048
2026-050
2026-060
2026-0710
2026-080
2026-090

Severity

How the 40 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1230%
  • High1845%
  • Medium923%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Xrdp.

  1. CVE-2026-55639xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)5.3
  2. CVE-2026-55626xrdp: No authentication required with Xvnc backend on RHEL 98.0
  3. CVE-2026-55238xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads5.3
  4. CVE-2026-54538xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER7.5
  5. CVE-2026-44978xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification5.3
  6. CVE-2026-44178xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow8.8
  7. CVE-2026-55645xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)6.5
  8. CVE-2026-42218XRDP is vulnerable to a server timing attack, leading to user enumeration5.3
  9. CVE-2026-41521xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass8.2
  10. CVE-2026-41252xrdp: lib_palette_update Heap Buffer Overflow & RCE9.8
  11. CVE-2026-35512xrdp: Heap buffer overflow in EGFX channel8.8
  12. CVE-2026-33689xrdp: Pre-authentication out-of-bounds reads in channel parsers9.1
  13. CVE-2026-33145xrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesman6.3
  14. CVE-2026-32624xrdp: Heap buffer overflow in xrdp_sec_process_logon_info() via incorrect g_strncat length calculation6.5
  15. CVE-2026-33516xrdp: Pre-authentication out-of-bounds reads in RDP capability and channel parsers9.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store