CVE-2026-55639: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with G
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55639
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-556390.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55639 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for xrdp is an
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-55626: xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user se…nvd · 2026-07-20
- mediumCVE-2026-55645: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concernin…nvd · 2026-07-20
- mediumCVE-2026-55238: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concernin…nvd · 2026-07-20
- highCVE-2026-54538: xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered wher…nvd · 2026-07-20
- mediumCVE-2026-44978: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read…nvd · 2026-07-20
- highCVE-2026-44178: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overf…nvd · 2026-07-20
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01