CVE-2026-44978 is a heap out-of-bounds read vulnerability within the FIPS-specific receive paths of xrdp, an open-source RDP server. The vulnerability exists in versions 0.10.6 and prior. It is not exploitable in the default configuration of xrdp. The vulnerability is only exploitable when the security layer is set to security_layer=negotiate or security_layer=rdp, and the crypto level is changed to crypt [truncated]
CVE-2026-44178 is a high-severity heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism of xrdp, an open-source RDP server. The vulnerability exists in versions 0.10.6 and prior. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result [truncated]
CVE-2026-42218 is a timing side-channel vulnerability in xrdp, an open source RDP server. Versions 0.10.6 and prior are affected, allowing remote attackers to infer the existence of a username on the system via username enumeration. This issue has been fixed in version 0.10.6.1. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of xrdp versions 0.10.6 and prior should update to ver [truncated]
CVE-2026-41521 is an integer overflow vulnerability in xrdp, an open source RDP server, affecting versions 0.10.6 and prior. The vulnerability occurs in the vnc-any connection mode of xrdp. A remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation. This results in an undersized allocation for the image buffer. When the incoming image data is [truncated]
CVE-2026-41252 is a critical vulnerability in xrdp, an open-source RDP server. The issue is caused by a missing bounds check, leading to a heap-based buffer overflow when operating in vnc-any mode. This occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted mes [truncated]