These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:58.670Z and has not been modified since then. FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. This vulnerability can be exploited by a malicious RDP serve [truncated]
CVE-2026-67293 is a critical vulnerability in FreeRDP, a popular open-source implementation of the Remote Desktop Protocol (RDP). The vulnerability, caused by improper certificate hostname validation, allows attackers to bypass TLS server authentication under certain conditions, potentially leading to unauthorized access. System administrators and security teams should assess their exposure, verify their [truncated]
A buffer over-disclosure vulnerability exists in FreeRDP before version 3.29.0. The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload. A malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload.
CVE-2026-67291 is a heap out-of-bounds read vulnerability in FreeRDP before version 3.29.0. The issue occurs in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in a client crash. This vulnerability has a CVSS score of 8 [truncated]
CVE-2026-67290 is a critical vulnerability in FreeRDP's TSMF FFmpeg decoder, allowing for a heap out-of-bounds read when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. This vulnerability has a high CVSS score of 8.7, indicating a high-priority risk. Organizations using FreeRDP versions before 3.29.0 should prioritize patching. Affected operators, platforms, and security teams should [truncated]
FreeRDP before version 3.29.0 is vulnerable to a critical issue (CVSS Score: 9.3) that allows a malicious RDP server to inject arbitrary headers or requests into the HTTP proxy CONNECT request. This occurs because FreeRDP does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. Organizations using FreeRDP for remote desktop connections should be aware [truncated]
The CVE-2026-67288 vulnerability exists in FreeRDP before version 3.29.0, which contains a null pointer dereference in smartcard cache request decoders. This vulnerability allows attackers to cause client process termination via crafted smartcard cache requests when smartcard emulation is enabled. Users of affected FreeRDP deployments should prioritize patching or upgrading to version 3.29.0 or later. The [truncated]
FreeRDP before 3.29.0 contains multiple TLS certificate identity validation weaknesses. This CVE record was published on 2026-08-01T13:16:57.487Z and has not been modified since then. The vulnerability affects users of FreeRDP versions before 3.29.0, administrators of systems using FreeRDP, and security teams monitoring for TLS certificate validation bypass vulnerabilities. The weaknesses are located in t [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:57.320Z and has not been modified since then. FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigg [truncated]
CVE-2026-64624 is a high-severity vulnerability in FreeRDP before 3.28.0. The vulnerability occurs because FreeRDP treats lines beginning with a forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, [truncated]
CVE-2026-64621 is a critical double-free vulnerability in FreeRDP before version 3.28.0. The vulnerability exists in the freerdp_client_rdp_file_apply_to_settings() function when parsing the selectedmonitors field of a .rdp connection file. An attacker can exploit this vulnerability by convincing a victim to open a crafted .rdp file with oversized monitor tokens, potentially leading to a size-controlled d [truncated]
A heap-based buffer overflow vulnerability exists in FreeRDP before version 3.28.0 in the crypto_rsa_common() function. The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. This vulnerability could allow an unauthenticated attacker to cause a de [truncated]
CVE-2026-57158 is a MEDIUM severity vulnerability in FreeRDP clients using the GFX pipeline, with an incomplete fix for CVE-2026-23530. A malicious RDP server can send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0. The vulnerability exists in the planar_decompress_plane_rle_only function in libfreerdp/codec/planar.c [truncated]
FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled are vulnerable to a heap read issue. This issue allows a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. The vulnerability is fixed in version 3.28.0. Users of FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled should review and apply the provided pat [truncated]
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fix [truncated]
CVE-2026-55827 is a heap out-of-bounds write vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. This issue allows a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content when FreeRDP clients are launched with the non-default /cache:codec:rfx option. Affected product deployments should be identified, and owners assigned for follo [truncated]
CVE-2026-56297 is a high-severity use-after-free vulnerability in FreeRDP before 3.22.0. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service. The vulnerability exists in dvcman_channel_close and dvcman_call_on_receive due [truncated]
FreeRDP versions prior to 3.26.0 contain an out-of-bounds heap write vulnerability in the planar bitmap decoder. The flaw exists in `freerdp_bitmap_decompress_planar()` within `libfreerdp/codec/planar.c`, where the function validates the X destination coordinate `nXDst` against the caller-provided destination stride (`nDstStep`) even when writing to an internal temporary buffer (`pTempData`). An attacker [truncated]
## Summary FreeRDP versions prior to 3.26.0 contain a heap use-after-free/double-free vulnerability in the RDPEAR NDR parser. A malicious RDP server can trigger memory corruption by reusing the same non-null NDR pointer reference ID across multiple logical pointer fields, causing the parser to assign the same heap object to multiple output fields. The generic destructor then independently frees both point [truncated]
A heap-buffer-overflow vulnerability exists in FreeRDP client versions prior to 3.26.0. The flaw resides in the `gdi_CacheToSurface` function, where a destination rectangle is validated after being clamped to UINT16_MAX, but the subsequent copy operation uses the original `cacheEntry->width/height` values. This mismatch allows a malicious RDP server to trigger an out-of-bounds heap write when the client h [truncated]
A heap-buffer-overflow vulnerability exists in FreeRDP's server-side clipboard (cliprdr) channel prior to version 3.26.0. A malicious RDP client can trigger this flaw by sending a CB_CLIP_CAPS PDU with a malformed capabilitySetLength value that is too small. This memory corruption can crash the server process, resulting in remote denial of service, and may be exploitable for code execution. The vulnerabil [truncated]
A heap-buffer-overflow vulnerability exists in FreeRDP versions prior to 3.26.0 within the gdi_CacheToSurface function. The flaw stems from a validation logic error: rectangle coordinates are clamped to UINT16_MAX during bounds checking, but subsequent copy operations use unclamped cache entry dimensions. This discrepancy allows a malicious RDP server to trigger out-of-bounds heap writes, potentially lead [truncated]
CVE-2026-33984 is a heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in the resize_vbar_entry() function in libfreerdp/codec/clear.c. Prior to version 3.24.2, an attacker can exploit this vulnerability by providing malicious pixel data, leading to a heap buffer overflow. This issue has been patched in version 3.24.2. Users should [truncated]
CVE-2026-31806 is a critical heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in the gdi_surface_bits() function, which processes SURFACE_BITS_COMMAND messages sent by the RDP server. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size, leading to a heap buffer overflow. [truncated]
CVE-2026-26965 is a heap out-of-bounds write vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability allows a remote, unauthenticated attacker to perform a heap out-of-bounds write with attacker-controlled offset and pixel data on any connecting FreeRDP client. This can lead to control-flow–relevant corruption, including the overwriting of a function pointer. The [truncated]
CVE-2026-26955 is a heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A malicious RDP server can trigger the vulnerability by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. This allows attacker-controlled data to reach image copy routines that write into surface data without bounds enforcement. The vulnerability [truncated]
CVE-2026-24678 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability, fixed in version 3.22.0, is a use-after-free issue in the ecam_channel_write function. This occurs when a capture thread sends sample responses using a freed channel callback after a device channel close. The vulnerability has a CVSS score of 8.7 and is considered HIGH sever [truncated]
CVE-2026-23884 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability, caused by offscreen bitmap deletion leaving `gdi->drawing` pointing to freed memory, can lead to a use-after-free (UAF) condition when related update packets arrive. This can cause a crash (DoS) and potentially lead to heap corruption with code-execution risk, depending on a [truncated]
CVE-2026-23534 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A client-side heap buffer overflow occurs when crafted band coordinates allow writes past the end of the destination surface buffer. A malicious server can trigger a client-side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code-execution risk depending on allo [truncated]
CVE-2026-23532 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A client-side heap buffer overflow occurs due to a mismatch between destination rectangle clamping and the actual copy size in the FreeRDP client’s `gdi_SurfaceToSurface` path. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruptio [truncated]