Critical CVE Fixes for FreeRDP in Fedora and Mageia

Critical CVE Fixes for FreeRDP in Fedora and Mageia

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

Recent advisories detail critical security updates for FreeRDP clients in Fedora and Mageia. Fedora 43 and 44 have patched multiple CVEs, including CVE-2026-22852, CVE-2026-22854, and CVE-2026-22855, with a total of 34 vulnerabilities addressed. Mageia's update focuses on CVE-2026-22851, which is a denial-of-service vulnerability, among others. The vulnerabilities affect the xfreerdp and wlfreerdp clients used to connect to RDP servers. Users are urged to update their systems immediately to mitigate potential exploitation. The updates were released on September 8 and September 10, 2026, respectively, highlighting the urgency of patching these vulnerabilities. The advisories emphasize the importance of maintaining up-to-date systems to prevent security breaches.

Key Points: • Fedora and Mageia released critical updates for FreeRDP clients addressing multiple CVEs. • Key vulnerabilities include CVE-2026-22851, CVE-2026-22852, and CVE-2026-22854. • Users are strongly advised to apply the patches to prevent potential exploitation.

Ask AI about this cluster

Timeline

2026-01-14
CVE-2026-22851 published
CVE-2026-22851, a critical DoS vulnerability, was published affecting FreeRDP clients.
Linuxsecurity
2026-01-14
CVE-2026-22852 published
CVE-2026-22852, another critical vulnerability, was also disclosed on this date.
Linuxsecurity
2026-01-14
CVE-2026-22855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-14
CVE-2026-22854 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-14
CVE-2026-22858 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-14
CVE-2026-22856 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-14
CVE-2026-22859 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-14
CVE-2026-22853 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-19
CVE-2026-23732 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-19
CVE-2026-23532 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE