Neutrinolabs maintains xRDP, a widely deployed open-source remote desktop protocol implementation that enables headless Linux systems to serve graphical remote sessions, positioning it as a foundational component in many server and virtualization environments. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, reflecting the memory-safety hazards inherent to a C-based network protocol parser handling untrusted input from remote clients. The recurring exposure centers on a cluster of buffer-overflow and out-of-bounds access weakness classes—including stack-based and heap-based buffer overflows, classic buffer-copy flaws, and out-of-bounds reads and writes—that arise from insufficient input validation and bounds checking in the protocol handling layer. Defenders should treat xRDP instances, particularly those internet-facing or accessible from untrusted networks, as high-risk and prioritize patching; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neutrinolabs over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41252CRITICAL xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The i | Jul 20, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-41521CRITICAL xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A | Jul 20, 2026 | 9.1 | 37 | NO | NO |
CVE-2025-68670CRITICAL xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when pro | Jan 27, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-44178HIGH xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding dat | Jul 20, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-54538HIGH xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protoco | Jul 20, 2026 | 7.5 | 32 | NO | NO |
CVE-2022-23480CRITICAL xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a buffer over flow in devre | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23478CRITICAL xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a Out of Bound Write in xrd | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23477CRITICAL xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a buffer over flow in audin | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23468CRITICAL xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP).
xrdp < v0.9.21 contain a buffer over flow in xrdp_ | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-55645MEDIUM xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client Control PDUs. During the RDP connection sequence, the parse | Jul 20, 2026 | 6.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neutrinolabs.
Media articles that mention a CVE ID that affects a product developed by Neutrinolabs — matched by CVE ID, not by vendor name.