xrdp Pre-Authentication Remote Code Execution | MSSP Advisory

Critical
DateMay 8, 2026
📋Executive Summary
CVE-2025-68670 is a pre-authentication remote code execution vulnerability in xrdp server, discovered during a Kaspersky USB Redirector security assessment. The flaw allows attackers to compromise systems without authentication credentials. Project maintainers have released patches for the vulnerability.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools likely depend on xrdp for Linux connections to client networks, making this a direct pathway into your infrastructure and every client you manage. Client environments running Linux servers with xrdp exposed are sitting ducks for immediate compromise, and explaining why you missed this advisory will be uncomfortable.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.