What is CVE-2026-66402?
Multiple TLS certificate identity validation weaknesses have been found in FreeRDP versions before 3.29.0, specifically in certificate hostname matching functions. This could allow man-in-the-middle attacks on secure RDP connections. Users should immediately update FreeRDP to version 3.29.0 or later.
Azərbaycanca: FreeRDP-nin 3.29.0 versiyasından əvvəlki versiyalarında TLS sertifikat şəxsiyyətinin yoxlanılmasında çoxsaylı zəifliklər aşkar edilib. Bu, təhlükəsiz RDP bağlantılarında ortadakı adam (man-in-the-middle) hücumlarına şərait yarada bilər. İstifadəçilər dərhal FreeRDP-ni 3.29.0 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: FreeRDP
FAQ2
Which versions of FreeRDP are affected by CVE-2026-66402?
All FreeRDP versions prior to 3.29.0 are affected by this vulnerability.
What type of threat can CVE-2026-66402 lead to?
This vulnerability could allow man-in-the-middle attacks on secure RDP connections.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.