OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96541

HIGH · CVSS 7.5 EPSS 0.79%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A denial-of-service vulnerability in gnome-remote-desktop allows unauthenticated remote attackers to exploit connection-throttling slots by opening RDP connections without completing the handshake, effectively retaining these slots indefinitely. This can lead to exhaustion of the global connection limit, preventing legitimate RDP clients from connecting. Organizations using gnome-remote-desktop should prioritize patching this flaw to mitigate potential service disruptions.

CVE
CVE-2026-96541
Severity
HIGH
CVSS
7.5
EPSS
0.79%

Original NVD Description

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.