FreeRDP vulnerabilities
21 CVEs tracked
FreeRDP is prominently featured in this reporting period with multiple critical security flaws identified in versions prior to 3.29.0 (<=3.28.0). Key themes include a lack of input validation in the RDP redirection field when using HTTP proxies, multiple TLS certificate identity validation weaknesses, a null pointer dereference in smartcard device control, and several client-side heap use-after-free and out-of-bounds read vulnerabilities when AsyncUpdate is enabled. Defenders should immediately update FreeRDP to version 3.29.0 or later, carefully review configurations where 'AsyncUpdate' is active, and remain vigilant against potential memory exhaustion attacks via malicious RD Gateway endpoints.
Azərbaycanca: FreeRDP, hesabat dövründə ciddi təhlükəsizlik problemləri ilə önə çıxır və 3.29.0 versiyasından əvvəlki bütün versiyalarda (<=3.28.0) kritik zəifliklər aşkarlanıb. Əsas mövzular arasında HTTP proxy istifadəsi zamanı RDP yönləndirmə sahəsində daxiletmə doğrulamasının olmaması, TLS sertifikat şəxsiyyətinin yoxlanılması zəiflikləri, smartcard cihaz idarəetmə sorğularında null pointer dereference xətası və AsyncUpdate aktiv olduqda müştəri tərəfində heap use-after-free və out-of-bounds read problemləri yer alır. Müdafiəçilər dərhal FreeRDP-ni 3.29.0 və ya daha yuxarı versiyaya yeniləməli, xüsusilə 'AsyncUpdate' funksiyasının aktiv olduğu konfiqurasiyaları nəzərdən keçirməli və RD Gateway bağlantıları üzərindən gələn potensial yaddaş tükənməsi hücumlarına qarşı sayıq olmalıdır.
This vendor's CVEs21
- CVE-2026-68580EPSS 0.24%
- CVE-2026-68579EPSS 0.27%
- CVE-2026-67306EPSS 0.27%
- CVE-2026-67305EPSS 0.49%
- CVE-2026-67304EPSS 0.35%
- CVE-2026-67303EPSS 0.24%
- CVE-2026-67302EPSS 0.31%
- CVE-2026-67301EPSS 0.34%
- CVE-2026-67300EPSS 0.33%
- CVE-2026-67299EPSS 0.33%
- CVE-2026-67298EPSS 0.38%
- CVE-2026-67297EPSS 0.34%
- CVE-2026-67296EPSS 0.34%
- CVE-2026-67294EPSS 0.27%
- CVE-2026-67292EPSS 0.26%
- CVE-2026-67291EPSS 0.34%
- CVE-2026-67290EPSS 0.43%
- CVE-2026-67289EPSS 0.40%
- CVE-2026-67288EPSS 0.35%
- CVE-2026-66402EPSS 0.29%
- CVE-2026-66401EPSS 0.15%
This hub is built from skopnix's own reporting on FreeRDP: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.