discovered 03 Aug 2026
XWormRCE
→ View on GitHubXWorm RCE is a proof of concept tool that demonstrates a zero-click vulnerability within the XWorm plugin for RDP connections. It exploits a flaw where the server fails to validate client responses, allowing an attacker to execute commands on the victim's machine without user interaction. Notable features include the ability to exploit the vulnerability without initiating a connection command, showcasing its potential for remote code execution.