vulnerability CVE-2025-68670: discovering an RCE vulnerability in xrdp This report details a remote code execution (RCE) vulnerability, CVE-2025-68670, discovered in the Kaspersky xrdp server. The vulnerability exists within the xrdp_wm_parse_domain_information function due to a buffer overflow when processing domain names. Kaspersky addressed the issue by patching versions 0.10.5, 0.9.27… Securelist · May 8, 2026 Critical CVE-2025-68670buffer_overflowrcexrdp