CVE-2026-32623
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-32623 is a heap-based buffer overflow vulnerability in the NeutrinoRDP module of xrdp, an open-source RDP server. It affects xrdp versions through 0.10.5 and was disclosed on April 17, 2026, with a fix released the same day in version 0.10.6. The flaw exists only in environments where the NeutrinoRDP module has been explicitly compiled and enabled (not built by default). It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-131 (Incorrect Calculation of Buffer Size). When xrdp proxies RDP sessions through the NeutrinoRDP module, it fails to properly validate the size of reassembled fragmented virtual channel data against the allocated heap memory buffer, enabling an out-of-bounds write. Exploitation requires either control of a malicious downstream RDP server that xrdp is proxying to, or the ability to perform a Man-in-the-Middle (MitM) attack on the RDP session in transit. The vulnerability was reported by researchers credited as @exploitintel, @smittix, and @hessandrew (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation can result in heap memory corruption on the xrdp host, potentially leading to a Denial of Service (crash/service unavailability) or Remote Code Execution (RCE) with the privileges of the xrdp process. If RCE is achieved, an attacker could gain unauthorized access to the affected system, potentially enabling lateral movement within the network, credential theft, or further compromise of connected infrastructure. The impact is limited to systems where the NeutrinoRDP module is explicitly compiled and enabled (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.48%, reflecting a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires either control of a downstream RDP server or a MitM position, which raises the attack complexity and limits opportunistic exploitation (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify xrdp deployments that have been compiled with the NeutrinoRDP module enabled. This can be confirmed by running xrdp -v and checking for --enable-neutrinordp in the output, or by scanning for xrdp services (default port 3389) and probing version banners.
  2. Establish attacker-controlled RDP server: Set up a malicious RDP server that the target xrdp instance will proxy connections to, or position the attacker between the xrdp host and a legitimate downstream RDP server (MitM).
  3. Trigger fragmented virtual channel data: Send specially crafted RDP virtual channel data to the xrdp proxy that is fragmented across multiple PDUs, with the reassembled total size exceeding the allocated heap buffer.
  4. Exploit buffer overflow: The NeutrinoRDP module reassembles the fragments without proper size validation, causing a heap-based buffer overflow. Depending on heap layout and memory state, this may crash the xrdp process (DoS) or allow controlled memory corruption for RCE.
  5. Achieve objective: If RCE is successful, execute arbitrary commands with xrdp process privileges on the host system (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Unexpected xrdp crashes or segmentation faults in system logs (/var/log/xrdp.log, /var/log/syslog, or journalctl) coinciding with RDP proxy sessions; error messages related to virtual channel data reassembly.
  • Process: xrdp process terminating abnormally or restarting repeatedly; unexpected child processes spawned by xrdp with unusual arguments.
  • Network: Unusual or unexpected downstream RDP server connections initiated by the xrdp host; RDP traffic to unfamiliar IP addresses on port 3389; anomalous fragmented RDP virtual channel PDUs in network captures.
  • File System: New or modified files in xrdp working directories created by the xrdp service account following an RDP proxy session; unexpected binaries or scripts dropped on the system.

Mitigation and workarounds

Upgrade xrdp to version 0.10.6 or later, which contains the fix for this vulnerability (xrdp Release). Organizations can verify exposure by running xrdp -v and checking for --enable-neutrinordp; if the flag is absent, the system is not affected. As a workaround for systems that cannot immediately upgrade, disable or recompile xrdp without the NeutrinoRDP module. Additionally, implement network-level controls to restrict which downstream RDP servers xrdp is permitted to proxy to, and monitor for anomalous RDP session activity (GitHub Advisory, Red Hat).

Community reactions

The vulnerability was credited to researchers @exploitintel, @smittix, and @hessandrew in the official xrdp v0.10.6 release notes, indicating responsible disclosure (xrdp Release). Red Hat tracked the issue via Bugzilla and assigned it high priority/severity (Red Hat Bugzilla). FreeBSD and openSUSE security teams also issued advisories and package updates in response to the disclosure. Coverage has been limited to vulnerability databases and Linux distribution security channels, with no significant broader media attention observed.

Additional resources


SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-55626HIGH7.3
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management