Critical FreeRDP Vulnerabilities in Ubuntu 25.10 and 24.04 LTS

Critical FreeRDP Vulnerabilities in Ubuntu 25.10 and 24.04 LTS

First seen 18 Mar 2026, 21:14 UTC UbuntuLinuxsecurity 89% similarity 70.5

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in FreeRDP, affecting Ubuntu 25.10 and 24.04 LTS. The flaws allow remote attackers to exploit improperly handled RDP packets, potentially leading to denial of service or arbitrary code execution. Affected CVEs include CVE-2026-22851 through CVE-2026-27951, with several published between January 14 and February 25, 2026. Users are advised to update their systems to the latest package versions to mitigate these vulnerabilities. The specific package versions required are libfreerdp3-3 3.16.0+dfsg-2ubuntu0.3 for Ubuntu 25.10 and libfreerdp3-3 3.5.1+dfsg1-0ubuntu1.4 for Ubuntu 24.04 LTS. A standard system update will apply the necessary changes. The vulnerabilities pose a significant risk due to the potential for remote exploitation.

Key Points: • FreeRDP vulnerabilities allow remote denial of service and arbitrary code execution. • Affected systems include Ubuntu 25.10 and 24.04 LTS with specific package versions to update. • Multiple CVEs were published between January and February 2026, indicating a serious issue.

ThreatCluster AI How this analysis works

Timeline

2026-01-14
CVE-2026-22851, CVE-2026-22852, CVE-2026-22853, CVE-2026-22854, CVE-2026-22855, CVE-2026-22856, CVE-2026-22857, CVE-2026-22858, CVE-2026-22859 published
2026-01-19
CVE-2026-23530, CVE-2026-23531, CVE-2026-23532, CVE-2026-23533, CVE-2026-23534, CVE-2026-23883, CVE-2026-23884 published
2026-01-19
CVE-2026-23732 published
2026-02-25
CVE-2026-25941, CVE-2026-25942, CVE-2026-25952, CVE-2026-25953, CVE-2026-25954, CVE-2026-25955, CVE-2026-25959, CVE-2026-26271, CVE-2026-26955, CVE-2026-26965, CVE-2026-26986, CVE-2026-27015, CVE-2026-27950, CVE-2026-27951 published
2026-02-25
CVE-2026-25997 published
2026-03-18
Ubuntu releases patch for FreeRDP vulnerabilities

Community

Browse all →

Tracked Entities in This Story