Critical Buffer Overflow Vulnerability in FreeRDP Disclosed
Article Content
- •CVE-2026-91959 affects FreeRDP versions before 3.31.0.
- •Attackers can exploit this vulnerability to crash FreeRDP clients via malicious BIND_ACK PDUs.
- •Immediate updates are recommended to mitigate the denial-of-service risk.
CVE-2026-91959 is a buffer over-read vulnerability affecting FreeRDP versions prior to 3.31.0, allowing attackers to crash clients via malicious BIND_ACK PDUs. This flaw impacts users connecting through the Remote Desktop Gateway, creating a denial-of-service condition. Exploitation requires user interaction to connect to a compromised gateway. The vulnerability was published on September 15, 2026, and affects applications embedding FreeRDP for RDP connectivity. The issue arises from insufficient validation in the rts_read_result function, leading to out-of-bounds reads. Security advisories recommend immediate updates to mitigate risks. The vulnerability has been confirmed to cause crashes in default builds of FreeRDP.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-33952 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…