Two high-severity vulnerabilities were disclosed in xrdp affecting versions through 0.10.5, exposing both remote session integrity and local privilege boundaries. CVE-2026-32105 allows an unauthenticated attacker with man-in-the-middle capability to alter encrypted RDP traffic without detection because xrdp does not verify the MAC signature on received packets when the Classic RDP Security layer is used. The flaw does not affect deployments that enforce TLS, and administrators unable to upgrade immediately were advised to set:
security_layer=tls
A second flaw, CVE-2026-32107, affects xrdp's session execution component and can let an authenticated local attacker gain root privileges if the privilege-drop operation fails and child processes continue executing with elevated rights. The issue requires local access and an additional exploit path, but it can lead to arbitrary code execution with full system impact. Both vulnerabilities were fixed in xrdp 0.10.6, making upgrade the primary remediation for exposed servers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public advisories described two xrdp flaws: CVE-2026-32105, where MAC signatures on received encrypted RDP packets were not verified in non-TLS mode, and CVE-2026-32107, where sesexec child processes could continue with root privileges if setuid failed. Both disclosures stated the issues affected xrdp versions through 0.10.5 and were fixed in 0.10.6.
xrdp released version 0.10.6 to fix CVE-2026-32105, an integrity bypass in non-TLS Classic RDP Security mode, and CVE-2026-32107, a fail-open privilege drop flaw in sesexec that could let a local authenticated attacker gain root. Systems unable to upgrade were advised to enforce TLS to mitigate CVE-2026-32105.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.