PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64624 FreeRDP CVE debrief

CVE-2026-64624 is a high-severity vulnerability in FreeRDP before 3.28.0. The vulnerability occurs because FreeRDP treats lines beginning with a forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction. The vulnerability has a high CVSS score of 8.5 and is classified as HIGH.

Vendor
FreeRDP
Product
Unknown
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-23
Advisory published
2026-07-20
Advisory updated
2026-07-23

Who should care

Users and administrators of FreeRDP versions before 3.28.0 should be aware of this vulnerability and take steps to mitigate it. This includes updating to version 3.28.0 or later, and being cautious when opening RDP files from untrusted sources. The vulnerability can be exploited without user interaction, and attackers can execute arbitrary commands, bypass certificate validation, or expose local filesystems.

Technical summary

The vulnerability occurs because FreeRDP does not properly validate RDP files, allowing attackers to inject malicious commands. The /rdp2tcp option can be used to execute arbitrary commands, /cert:ignore can be used to bypass certificate validation, and /drive can be used to expose local filesystems. FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files.

Defensive priority

High

Recommended defensive actions

  • Update FreeRDP to version 3.28.0 or later
  • Be cautious when opening RDP files from untrusted sources
  • Validate RDP files before opening them
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-20T22:17:18.600Z and was last modified on 2026-07-23T05:16:38.203Z. The NVD entry is currently Received. The vulnerability occurs because FreeRDP treats lines beginning with a forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. The evidence is limited, and defenders should verify the affected scope and severity. The CVE record was last modified on 2026-07-23T05:16:38.203Z, and the NVD entry is currently Received.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T22:17:18.600Z and has not been modified since then. The NVD entry is currently Received.