SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-55639

MEDIUM · CVSS 5.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The xrdp server versions 0.10.6 and earlier are vulnerable due to insufficient length validation during the parsing of Client Security Data in the connection sequence, allowing remote, unauthenticated attackers to exploit this flaw. This could lead to the disclosure of sensitive process memory contents, particularly when combined with other vulnerabilities. Organizations using affected versions should prioritize upgrading to version 0.10.6.1 to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55639
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%

Original NVD Description

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)