Skip to content
Critical Buffer Overflow Vulnerability in FreeRDP Disclosed

Critical Buffer Overflow Vulnerability in FreeRDP Disclosed

First seen 19 Sep 2026, 10:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 12:31 UTC
  • CVE-2026-91959 affects FreeRDP versions before 3.31.0.
  • Attackers can exploit this vulnerability to crash FreeRDP clients via malicious BIND_ACK PDUs.
  • Immediate updates are recommended to mitigate the denial-of-service risk.

CVE-2026-91959 is a buffer over-read vulnerability affecting FreeRDP versions prior to 3.31.0, allowing attackers to crash clients via malicious BIND_ACK PDUs. This flaw impacts users connecting through the Remote Desktop Gateway, creating a denial-of-service condition. Exploitation requires user interaction to connect to a compromised gateway. The vulnerability was published on September 15, 2026, and affects applications embedding FreeRDP for RDP connectivity. The issue arises from insufficient validation in the rts_read_result function, leading to out-of-bounds reads. Security advisories recommend immediate updates to mitigate risks. The vulnerability has been confirmed to cause crashes in default builds of FreeRDP.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-30
CVE-2026-33952 published
A related vulnerability concerning authentication length assertion was published, affecting FreeRDP.
Sentinelone
2026-09-15
CVE-2026-91959 published
The buffer over-read vulnerability in FreeRDP was disclosed, affecting versions prior to 3.31.0.
Sentinelone
2026-09-19
Security advisory issued
FreeRDP's GitHub advisory details the vulnerability and its impact, urging users to update.
github.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-33952 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed