Another Dozen Vulnerabilities Found In The X.Org Server & XWayland
With the assistance of AI, another dozen security vulnerabilities affecting both the conventional X.Org Server as well as XWayland were made public this evening.
The TrendAI Zero Day Initiative has uncovered twelve more security vulnerabilities affecting the conventional X.Org Server codebase as well as XWayland. The TrendAI Zero Day Initiative has uncovered numerous X.Org security issues in the past and building further upon a theme set a decade ago by a separate security researcher who remarked more than a decade ago, back in 2013 that
X.Org security is even "worse than it looks"
The newest round of X.Org Server and XWayland security disclosures include:
* CVE-2026-88812: XKB SetGeometry TextDoodad Double Free
* CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free
* CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free
* CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow
* CVE-2026-93518: XKB ResizeKeyType Numeric Truncation
* CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow
* CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write
* CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow
* CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow
* CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write
* CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read
* CVE-2026-93536: GestureBuildSprite Use-After-Free
Lots of use-after-free, buffer overflows, and out-of-bounds reads/writes continue to persist in the X.Org Server codebase.
These issues are present in versions prior to the new xorg-server-21.1.25 and xwayland-24.1.14.
All the details on these new security disclosures can be found via
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
