Critical xrdp Vulnerabilities in Fedora 44 and 42 Require Immediate Attention

Critical xrdp Vulnerabilities in Fedora 44 and 42 Require Immediate Attention

First seen 28 Apr 2026, 06:34 UTC Linuxsecurity 96% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical security update for Fedora 44 addresses multiple vulnerabilities in xrdp, including CVE-2026-32105, CVE-2026-32107, CVE-2026-32623, CVE-2026-32624, CVE-2026-33145, CVE-2026-33516, CVE-2026-33689, and CVE-2026-35512. These vulnerabilities allow for remote code execution, privilege escalation, and denial of service attacks. The flaws are particularly concerning as they affect a widely used RDP server compatible with various clients, including FreeRDP and Microsoft RDP. The vulnerabilities were published on April 17, 2026, and have been addressed in the latest updates. Users are advised to apply the patches immediately to mitigate potential exploitation. The issues were identified in versions prior to 0.10.6 of xrdp. The update also includes bug fixes and new features aimed at improving functionality. Organizations using affected versions are at risk of significant security breaches if they do not update promptly.

Key Points: • Multiple critical vulnerabilities in xrdp affect Fedora 44 and 42. • CVE-2026-32105 and CVE-2026-32107 allow for privilege escalation and data integrity issues. • Immediate patching is required to prevent remote code execution and denial of service attacks.

ThreatCluster AI

Timeline

2026-04-17
CVE-2026-32105, CVE-2026-32107, CVE-2026-32623, CVE-2026-32624, CVE-2026-33145, CVE-2026-33516, CVE-2026-33689, CVE-2026-35512 published
2026-04-28
Critical security update for Fedora 44 released

Community

Browse all →