Skip to content
Critical RDP Vulnerabilities Enable Remote Code Execution

Critical RDP Vulnerabilities Enable Remote Code Execution

First seen 29 Sep 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 20:19 UTC
  • •Critical heap overflow and information leak vulnerabilities in FreeRDP.
  • •Exploitation allows remote code execution without user credentials.
  • •Affected versions include FreeRDP 2.x and 3.x and linked clients like Remmina.

Two significant vulnerabilities in FreeRDP have been reported, allowing remote code execution (RCE) and information leaks. The first vulnerability, a heap overflow, can lead to RCE when exploited in conjunction with a memory leak that exposes uninitialized heap memory. Both vulnerabilities affect FreeRDP versions 2.x and 3.x, as well as clients like Remmina and others that link to libfreerdp. Attackers can exploit these vulnerabilities without needing credentials, posing a severe risk to users who connect to malicious RDP servers. The vulnerabilities have been confirmed in various versions, with specific exploits demonstrated in dynamic tests. Users are urged to apply patches immediately to mitigate these risks. The vulnerabilities have been assigned CVE identifiers but specific CVEs were not disclosed in the articles.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
Vulnerabilities disclosed
Julien Lair from Quarkslab reported two vulnerabilities in FreeRDP, enabling RCE and information leaks.
github.com
2026-09-29
Patch recommendation issued
Users are advised to update FreeRDP and related clients to mitigate the vulnerabilities.
github.com

More articles in this cluster (2)