CVE-2026-32105Disclosure(neutrinolabs / xrdp)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch neutrinolabs xrdp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly generates signatures, the receiving logic lacks the necessary implementation to validate the 8-byte integrity signature, causing it to be silently ignored. An unauthenticated attacker with man-in-the-middle (MITM) capabilities can exploit this missing check to modify encrypted traffic in transit without detection. It does not affect connections where the TLS security layer is enforced. This issue has been fixed in version 0.10.6. If users are unable to immediately upgrade, they should configure xrdp.ini to enforce TLS security (security_layer=tls) to ensure end-to-end integrity.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xrdp

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-18); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
xrdp

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-17: 1Mentions · 2026-04-18: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-28: 104-1704-1804-28
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-04-182
Disclosure2
2026-04-281
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32105 xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted R… https://www.cve.org/CVERecord?id=CVE-2026-32105

    Post summary

    The post notes a MAC verification flaw in xrdp versions through 0.10.5, providing a brief technical description but no evidence of PoC, exploitation, or patch.

    010201.1K
    57.7K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 44 and 42 ship critical xrdp flaws (CVE-2026-32105, -32107, -32623, -32624, -33145, -33516, -33689, -35512) enabling RCE, privilege escalation and DoS, patch to 0.10.6 now. https://threatcluster.io/cluster/critical-xrdp-vulnerabilities-in-fedora-44-and-42-require-im-c7dd5323

    Post summary

    The post alerts that Fedora 44 and 42 include critical xrdp flaws (CVE‑2026‑32105, ‑32107, ‑32623, ‑32624, ‑33145, ‑33516, ‑33689, ‑35512) that enable remote code execution, privilege escalation, and denial‑of‑service, and notes a patch (0.10.6) is available now.

    00000128
    166 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32105 xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted R… https://www.cve.org/CVERecord?id=CVE-2026-32105 ----- Traducción: CVE-2026-32105 xrd… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-32105 and explains that xrdp versions 0.10.5 and earlier lack MAC verification for encrypted RDP sessions, but does not provide any PoC, exploit, or patch information.

    0000050
    72 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32105: xrdp:... MITM paradise: xrdp silently ignores MAC signatures in classic RDP mode, letting attackers modify encrypted traffic undetected #RDPsecurity #MITM. https://zerodaysignal.com/vulnerability/CVE-2026-32105 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reveals a new CVE (CVE-2026-32105) affecting xrdp, highlighting a MAC signature bypass that enables MITM attacks, but no PoC, exploit code, patch, or active exploitation claims are provided.

    0000074
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appneutrinolabsxrdp---

Explore more