Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-44178

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 55.4%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-44178


Contact Us

Shodan ® - All rights reserved