Critical FreeRDP Vulnerabilities Affect Multiple Ubuntu Releases

Critical FreeRDP Vulnerabilities Affect Multiple Ubuntu Releases

First seen 16 Jun 2026, 11:21 UTC UbuntuLinuxsecuritylaunchpad.net 89% similarity 74.0

Article Content

Browse articles
ThreatCluster

A set of vulnerabilities in FreeRDP has been identified, affecting various Ubuntu versions including 24.04 LTS, 25.10, and 26.04 LTS. The most critical issue, CVE-2026-45700, allows for out-of-bounds heap writes, potentially leading to denial of service or arbitrary code execution. Other vulnerabilities addressed include CVE-2026-22858, CVE-2026-23732, and CVE-2026-25952, which were previously introduced in earlier updates. Users are advised to update their systems to mitigate these risks. The vulnerabilities were disclosed on May 29, 2026, and are part of a broader security update. Affected systems include Ubuntu 18.04 LTS through 26.04 LTS and their derivatives. The update is available through standard system updates and Ubuntu Pro for extended support.

Key Points: • CVE-2026-45700 poses a critical risk of denial of service or arbitrary code execution. • Multiple Ubuntu versions, including 24.04 LTS and 26.04 LTS, are affected by these vulnerabilities. • Users are urged to update their systems immediately to mitigate the identified risks.

ThreatCluster AI How this analysis works

Timeline

2026-01-14
CVE-2026-22858 published
A vulnerability in FreeRDP was disclosed, affecting memory handling.
Ubuntu
2026-01-19
CVE-2026-23732 published
Another vulnerability in FreeRDP was disclosed, related to memory management.
Ubuntu
2026-02-25
CVE-2026-25952 published
A third vulnerability affecting FreeRDP was disclosed, impacting system stability.
Ubuntu
2026-05-29
CVE-2026-45700 published
A critical vulnerability in FreeRDP was disclosed, allowing for potential exploits.
Linuxsecurity
2026-06-16
Security update released
Ubuntu released an update to address multiple vulnerabilities in FreeRDP.
Ubuntu

Community

Browse all →

Tracked Entities in This Story