PT-2026-33487 · Xrdp · Xrdp

·

CVE-2026-32105

·

Published

2026-04-17

·

Updated

2026-05-19

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6
Description xrdp fails to implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when the Classic RDP Security layer is used. Although signatures are generated by the sender, the receiving logic ignores the 8-byte integrity signature. This allows an unauthenticated attacker with man-in-the-middle (MITM) capabilities to modify encrypted traffic in transit without detection. This issue does not affect connections where the TLS security layer is enforced.
Recommendations Update to version 0.10.6. Configure xrdp.ini to enforce TLS security by setting security layer=tls to ensure end-to-end integrity.

Exploit

Fix

RCE

LPE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06985
CVE-2026-32105
GHSA-J2JM-C596-C5Q3
OPENSUSE-SU-2026:10816-1

Affected Products

Xrdp