These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-55639 vulnerability affects xrdp, an open-source RDP server, specifically in the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request. This vulnerability class concerns insufficient length validation for incoming data blocks during the initial capability and security negotiation phase. The likely operational impact includes potential mem [truncated]
CVE-2026-55238 is a Denial of Service vulnerability in xrdp, an open-source RDP server. Versions 0.10.6 and prior are affected. The vulnerability concerns the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by send [truncated]
CVE-2026-54538 is a high-severity vulnerability in xrdp, an open-source RDP server. The issue causes the software to fail to properly validate the totalLength field within the RDP protocol control header during packet reception. This allows an unauthenticated remote attacker to exploit the vulnerability by sending a specially crafted packet that forces the xrdp process into an infinite, CPU-bound loop. Co [truncated]
CVE-2026-44978 is a heap out-of-bounds read vulnerability within the FIPS-specific receive paths of xrdp, an open-source RDP server. The vulnerability exists in versions 0.10.6 and prior. It is not exploitable in the default configuration of xrdp. The vulnerability is only exploitable when the security layer is set to security_layer=negotiate or security_layer=rdp, and the crypto level is changed to crypt [truncated]
CVE-2026-44178 is a high-severity heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism of xrdp, an open-source RDP server. The vulnerability exists in versions 0.10.6 and prior. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result [truncated]
CVE-2026-42218 is a timing side-channel vulnerability in xrdp, an open source RDP server. Versions 0.10.6 and prior are affected, allowing remote attackers to infer the existence of a username on the system via username enumeration. This issue has been fixed in version 0.10.6.1. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of xrdp versions 0.10.6 and prior should update to ver [truncated]
CVE-2026-41521 is an integer overflow vulnerability in xrdp, an open source RDP server, affecting versions 0.10.6 and prior. The vulnerability occurs in the vnc-any connection mode of xrdp. A remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation. This results in an undersized allocation for the image buffer. When the incoming image data is [truncated]
CVE-2026-41252 is a critical vulnerability in xrdp, an open-source RDP server. The issue is caused by a missing bounds check, leading to a heap-based buffer overflow when operating in vnc-any mode. This occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted mes [truncated]