NVD disclosure day

Published threat advisories for March 5, 2026

CVE advisoryUNKNOWN

CVE-2026-30794

RustDesk Client Improper Certificate Validation Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

The RustDesk Client has an improper certificate validation vulnerability that could allow an attacker to intercept and manipulate communications. This affects the client's TLS transport and HTTP API client modules, potentially compromising remote desktop session data and confidentiality. Confirmation of the client's pr

CVE advisoryUNKNOWN

CVE-2026-30790

RustDesk Client Password Interception and Offline Brute Forcing Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in RustDesk's API login process could allow attackers to intercept credentials via network sniffing, which can then be used for offline brute-forcing. This affects the Server Pro login over HTTP and is exploitable when the API is reachable. This issue is relevant due to the potential for unauthorized ac

CVE advisoryMEDIUM

CVE-2026-30789

RustDesk Client Session Replay Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the RustDesk client could allow an attacker to bypass authentication by reusing session information, potentially enabling unauthorized access. This issue impacts the client's login and peer authentication modules across various operating systems, making it important to determine if this technology is