RustDesk is an open-source remote-access software platform whose vulnerability profile centers on its core client and server products and skews strongly toward critical-severity outcomes. The recurring weaknesses—weak password hashing, cleartext credential transmission, improper certificate validation, and authorization gaps—reflect the authentication and transport-security demands inherent to a remote-desktop platform that must protect administrative access and sensitive data in motion. Defenders should prioritize patching this vendor's releases and validate secure configuration of trust anchors and credential handling; current exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rustdesk over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57850HIGH RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, | Jul 10, 2026 | 8.3 | 36 | NO | NO |
CVE-2026-58056HIGH RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A | Jun 28, 2026 | 7.6 | 35 | NO | NO |
CVE-2026-30793CRITICAL Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge mo | Mar 5, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-30789CRITICAL Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-cli | Mar 5, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-30783CRITICAL A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) al | Mar 5, 2026 | 9.8 | 27 | NO | NO |
CVE-2024-25140CRITICAL A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5 | Feb 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-30796HIGH Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS | Mar 5, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-30792HIGH A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) | Mar 5, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-30798HIGH Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linu | Mar 5, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-30797HIGH Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) al | Mar 5, 2026 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rustdesk.
Media articles that mention a CVE ID that affects a product developed by Rustdesk — matched by CVE ID, not by vendor name.