Linuxsecurity Critical FreeRDP Vulnerabilities in Ubuntu 25.10 and 24.04 LTS
Article Content
- •FreeRDP vulnerabilities allow remote denial of service and arbitrary code execution.
- •Affected systems include Ubuntu 25.10 and 24.04 LTS with specific package versions to update.
- •Multiple CVEs were published between January and February 2026, indicating a serious issue.
Multiple vulnerabilities were discovered in FreeRDP, affecting Ubuntu 25.10 and 24.04 LTS. The flaws allow remote attackers to exploit improperly handled RDP packets, potentially leading to denial of service or arbitrary code execution. Affected CVEs include CVE-2026-22851 through CVE-2026-27951, with several published between January 14 and February 25, 2026. Users are advised to update their systems to the latest package versions to mitigate these vulnerabilities. The specific package versions required are libfreerdp3-3 3.16.0+dfsg-2ubuntu0.3 for Ubuntu 25.10 and libfreerdp3-3 3.5.1+dfsg1-0ubuntu1.4 for Ubuntu 24.04 LTS. A standard system update will apply the necessary changes. The vulnerabilities pose a significant risk due to the potential for remote exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ubuntu and CVE-2026-22851 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical CVE Fixes for FreeRDP in Fedora and Mageia Recent advisories detail critical security updates for FreeRDP clients in Fedora and Mageia. Fedora 43 and 44 have patched multiple CVEs, including CVE-2026-22852, CVE-2026-22854, and CVE-2026-22855, with a total of 34 vulnerabilities addressed. Mageia's update focuses on CVE-2026-22851, which is a denial-of-service…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…