
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32623 is a heap-based buffer overflow vulnerability in the NeutrinoRDP module of xrdp, an open-source RDP server. It affects xrdp versions through 0.10.5 and was disclosed on April 17, 2026, with a fix released the same day in version 0.10.6. The flaw exists only in environments where the NeutrinoRDP module has been explicitly compiled and enabled (not built by default). It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-131 (Incorrect Calculation of Buffer Size). When xrdp proxies RDP sessions through the NeutrinoRDP module, it fails to properly validate the size of reassembled fragmented virtual channel data against the allocated heap memory buffer, enabling an out-of-bounds write. Exploitation requires either control of a malicious downstream RDP server that xrdp is proxying to, or the ability to perform a Man-in-the-Middle (MitM) attack on the RDP session in transit. The vulnerability was reported by researchers credited as @exploitintel, @smittix, and @hessandrew (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation can result in heap memory corruption on the xrdp host, potentially leading to a Denial of Service (crash/service unavailability) or Remote Code Execution (RCE) with the privileges of the xrdp process. If RCE is achieved, an attacker could gain unauthorized access to the affected system, potentially enabling lateral movement within the network, credential theft, or further compromise of connected infrastructure. The impact is limited to systems where the NeutrinoRDP module is explicitly compiled and enabled (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.48%, reflecting a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires either control of a downstream RDP server or a MitM position, which raises the attack complexity and limits opportunistic exploitation (GitHub Advisory, Feedly).
xrdp -v and checking for --enable-neutrinordp in the output, or by scanning for xrdp services (default port 3389) and probing version banners./var/log/xrdp.log, /var/log/syslog, or journalctl) coinciding with RDP proxy sessions; error messages related to virtual channel data reassembly.Upgrade xrdp to version 0.10.6 or later, which contains the fix for this vulnerability (xrdp Release). Organizations can verify exposure by running xrdp -v and checking for --enable-neutrinordp; if the flag is absent, the system is not affected. As a workaround for systems that cannot immediately upgrade, disable or recompile xrdp without the NeutrinoRDP module. Additionally, implement network-level controls to restrict which downstream RDP servers xrdp is permitted to proxy to, and monitor for anomalous RDP session activity (GitHub Advisory, Red Hat).
The vulnerability was credited to researchers @exploitintel, @smittix, and @hessandrew in the official xrdp v0.10.6 release notes, indicating responsible disclosure (xrdp Release). Red Hat tracked the issue via Bugzilla and assigned it high priority/severity (Red Hat Bugzilla). FreeBSD and openSUSE security teams also issued advisories and package updates in response to the disclosure. Coverage has been limited to vulnerability databases and Linux distribution security channels, with no significant broader media attention observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."