Vulnerability Snapshot
CVE-2026-30790 is rated CRITICAL β exploitation is trivial or already observed in the wild and impact is severe. Patch immediately, not on the next maintenance window.
Affected technology: rustdesk_server, macos, linux_kernel, windows.
Executive Summary
Use of Password Hash With Insufficient Computational Effort, Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Server Pro /api login over the HTTP management channel) allows Interception (aka Sniffing) followed by offline Password Brute Forcing.
The controlled-host peer authentication channel is NOT affected: Client::secure_connection verifies the HBBS-signed host public key and negotiates an XSalsa20-Poly1305 secretbox session before the login proof is sent, so passive capture and relay man-in-the-middle do not expose it (capture-replay / CWE-294 withdrawn). On the Server Pro /api login path the proof is protected by TLS alone, is exposed under the automatic invalid-certificate downgrade (CVE-2026-30794), and is recoverable offline because it is a fast double SHA256 over a server-controlled salt and challenge with no slow KDF.
This vulnerability is associated with program files src
Why It Matters
CVE-2026-30790 is rated CRITICAL severity, requiring immediate attention from security teams.
CVSS Base Score: 9.8/10
EPSS (Exploit Prediction): 0.4% probability of exploitation in the next 30 days.
Affected Technologies
Vendors: rustdesk, apple, linux, microsoft
Products: rustdesk_server, macos, linux_kernel, windows
π‘οΈWhat Defenders Should Check
Use Vulnios to continuously monitor your exposure to CVE-2026-30790 and similar vulnerabilities.
References & Sources
How Vulnios Detects This
Vulnios scans for this vulnerability using Trivy and Grype for CVE matching against your container images and OS package manifests and KEV cross-check that flags any host where this CVE is already on CISA's exploited list. Run a scan against your environment to see whether you are exposed; findings are linked back to the original CVE record so triage starts with the patch path already known.
AI Security Advisor
Powered by Gemini
Get AI-powered security recommendations tailored to this specific threat β including risk assessment, detection guidance, MITRE ATT&CK mapping, and actionable remediation steps.
Affected Products
Sources
Related Threat Alerts
- More Cybersecurity Firms Disclose Impact From Klue Hack
- New Exploit Bypasses Appleβs Boot Defenses, Affects Millions of iPhones
- Fortinet Responds to FortiBleed Campaign
- Canadaβs Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
- Critical Vulnerability: CVE-2026-30789 β rustdesk, apple β rustdesk, iphone_os
- AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
Frequently Asked Questions
What is CVE-2026-30790?
CVE-2026-30790 is a critical-severity vulnerability tracked under the Common Vulnerabilities and Exposures program. Use of Password Hash With Insufficient Computational Effort, Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux,
Am I affected?
Check whether your environment runs rustdesk_server, macos, linux_kernel, windows. If you operate any of those, treat yourself as in scope until you have evidence otherwise. A Vulnios scan will identify the exact assets carrying the affected version.
How urgent is the response?
Critical: do not wait for your normal patch cycle. Verify exposure today, apply the vendor patch immediately, and add detection rules for any post-exploit indicators.
How do I remediate?
Apply the vendor patch listed in the upstream advisory linked under Sources. If the patch is not yet available, follow the vendor-supplied workaround (often a config flag or feature disable) and add detections for the published exploit pattern in your SIEM. Re-scan after the patch lands to confirm the finding clears.
Where can I track exploitation activity?
Watch CISA's Known Exploited Vulnerabilities catalog for CVE-2026-30790. Cross-reference with public exploit databases and your own SIEM/IDS for indicator-of-compromise patterns. Vulnios tracks KEV status automatically and surfaces it on the asset findings view.
How does Vulnios help with this?
Vulnios continuously cross-references your asset inventory against the live CVE feed (NVD, vendor advisories, CISA KEV, and curated OSINT). When a new CVE matches your environment, you get a prioritized finding with the severity, KEV status, exploit-prediction (EPSS), and a direct path to the vendor patch. You can start a free scan from the homepage.
Protect Your Organization
Monitor CVEs, scan for vulnerabilities, and get real-time threat alerts β all in one platform.
Get instant alerts on Telegram
Join our public channel for real-time critical CVE alerts.
Follow @vulnios