Neutrinolabs Xrdp — CVE-2026-41521 (Critical)

Date Jul 20, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Neutrinolabs · Xrdp
CVE CVE-2026-41521
Critical vendor advisory CVE-2026-41521

Summary

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a den

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 8.2) in Neutrinolabs Xrdp. Patch or mitigate promptly. EPSS percentile: 45%.

Operator check

Review CVE-2026-41521 in your asset inventory. Apply patches per vendor guidance and verify Xrdp is not exposed. CVSS score: 8.2. EPSS probability: 0.6%; percentile: 45%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.