SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-18358

HIGH · CVSS 7.5 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A vulnerability in the gnome-remote-desktop component of Red Hat Enterprise Linux allows unauthenticated remote attackers to bypass the connection throttler when RDP is enabled, leading to resource exhaustion through multiple parallel pre-authentication connections. This can prevent legitimate users from establishing RDP sessions, posing a significant risk to system availability. Organizations using Red Hat Enterprise Linux with RDP enabled should prioritize addressing this issue to safeguard against potential denial-of-service attacks.

CVE
CVE-2026-18358
Severity
HIGH
CVSS
7.5
EPSS
0.52%
Linux

Original NVD Description

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.