X.Org Server 26.1 has been released as the project’s first major feature update in roughly five years, succeeding the 21.1 series and marking a significant refresh of the long-running display server stack. The release, identified in one report as xorg-server 26.0.99.901, replaces the legacy Autoconf/Automake build system with Meson and introduces protocol and platform updates including DPMS 1.2 event support, XFixes 6.1, BSD DRM platform support, and expanded Xvfb capabilities.
The update also brings several security-relevant hardening changes across X.Org-based servers including Xorg, Xephyr, Xnest, Xvfb, Xwin, and Xquartz. Reports say the server now disallows byte-swapped clients by default and disables font server connections by default, while also changing log storage behavior for rootless mode and removing older components such as DMX, EXA, and shadow pixmap code. Xorg additionally now requires libpciaccess 0.19 because of a new API dependency, reflecting broader modernization of the codebase alongside the security improvements.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
The same day as the X.Org Server 26.1 RC1 announcement, XWayland 26.1 RC1 was also released. The reference notes X.Org Server 26.1 was less feature-rich than the XWayland 26.1 work in development.
X.Org Server 26.1 RC1 was tagged on 19 August 2026 as the first major feature release candidate for xorg-server in five years. The release candidate includes security-relevant hardening such as disallowing byte-swapped clients by default and disabling font server connections by default, alongside the Meson-only build transition and other updates.
The references identify the 21.1 branch as the prior major X.Org Server line and state it was released in 2021. Later 26.1 is described as the first major update since this branch.
A reference reports the release of X.Org Server 26.1.0, identified as xorg-server 26.0.99.901, as a new major update to the display server. It includes the Meson migration, Xwayland integration from the same source tree, protocol and configuration updates, BSD DRM support, rootless log path changes, expanded Xvfb support, and removal of DMX, EXA, and shadow pixmap code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
opennet.ru
Open sourcephoronix.com
Open sourcelists.x.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.