X.Org maintains the widely deployed X11 windowing system and related graphics infrastructure that sits at the foundation of Unix and Linux desktop environments, presenting a legacy codebase with substantial installed deployment reach. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and the exposure concentrates in core components including the X Server, XWayland, and the X11 client libraries. The recurring weakness classes—buffer boundary violations, out-of-bounds writes, use-after-free conditions, and input-validation flaws—reflect the memory-safety challenges inherent to aging native graphics code that handles untrusted display protocol data and font rendering. Defenders should prioritize X11-related updates in desktop and server environments where graphical access is exposed, particularly for systems running legacy or unpatched distributions; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by X.Org over time
Signals from CVEs in this vendor scope (169 CVEs).
169 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14665MEDIUM A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with th | Oct 25, 2018 | 6.6 | 57 | NO | YES |
CVE-1999-0526HIGH An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. | Jul 1, 1997 | 10.0 | 54 | NO | YES |
CVE-2026-56000HIGH Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to Comm | Jul 8, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-55999HIGH Local attackers with a X connection able to provide PCX fonts to the X
server xorg-server before 21.2.24 and xwayland before 24.1.13 could
cause a heap buffer overflow via SetFon | Jul 8, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-50261HIGH A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying | Jun 5, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-50260HIGH A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-afte | Jun 5, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-50258HIGH A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes( | Jun 5, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-50256HIGH A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a st | Jun 5, 2026 | 7.8 | 36 | NO | NO |
CVE-2021-31535CRITICAL LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side col | May 27, 2021 | 9.8 | 36 | NO | NO |
CVE-2019-17624HIGH "" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of se | Oct 16, 2019 | 7.8 | 36 | NO | YES |
Signals from CVEs in this vendor scope (169 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by X.Org.
Media articles that mention a CVE ID that affects a product developed by X.Org — matched by CVE ID, not by vendor name.