Skip to content
Critical Vulnerabilities in FreeRDP Affecting Remote Desktop Services

Critical Vulnerabilities in FreeRDP Affecting Remote Desktop Services

First seen 19 Sep 2026, 10:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 12:31 UTC
  • FreeRDP versions before 3.31.0 are vulnerable to critical issues.
  • Buffer over-read and denial of service vulnerabilities could disrupt remote desktop services.
  • Immediate patching is recommended to mitigate risks associated with these vulnerabilities.

Two significant vulnerabilities have been identified in FreeRDP versions prior to 3.31.0. The first vulnerability allows for a buffer over-read via the Remote Transport Gateway, while the second leads to a denial of service through desktop dimensions. These vulnerabilities could impact users relying on FreeRDP for remote desktop connections, potentially leading to service disruptions and data exposure. The vulnerabilities have been assigned CVE identifiers, but specific CVE numbers are not mentioned in the articles. Users are advised to prioritize patching these vulnerabilities to mitigate risks. The vulnerabilities were reported on September 16 and September 19, 2026, with advisories issued by VulnCheck. The current status indicates that these vulnerabilities require immediate attention from affected organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
Denial of Service vulnerability disclosed
FreeRDP before 3.31.0 is found vulnerable to denial of service via desktop dimensions.
VulnCheck
2026-09-19
Buffer over-read vulnerability disclosed
A buffer over-read vulnerability via the Remote Transport Gateway was reported for FreeRDP versions before 3.31.0.
VulnCheck

More articles in this cluster (2)