FreeRDP bug can run code
FreeRDP has a CERT-Bund advisory for 6 vulnerabilities in versions before 3.27.0. An attacker can exploit multiple vulnerabilities in FreeRDP to cause unspecified impacts, potentially execute arbitrary code, bypass security measures, manipulate data, disclose sensitive information, or trigger a denial-of-service condition.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 3.27.0Fix recorded 2 days ago
- Affected versions
- before 3.27.0
- Affects
- FreeRDP+3 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
An attacker can exploit multiple vulnerabilities in FreeRDP to cause unspecified impacts, potentially execute arbitrary code, bypass security measures, manipulate data, disclose sensitive information, or trigger a denial-of-service condition.
What to do
Check your FreeRDP version. If it is before 3.27.0, this advisory applies.
Update FreeRDP to 3.27.0 or newer.
Technical details
Affected software: FreeRDP, Sonstiges, UNIX, Windows
CERT-Bund describes FreeRDP as a freie Implementierung des Remote Desktop Protocol (RDP). An attacker can exploit multiple vulnerabilities in FreeRDP to cause unspecified impacts, potentially execute arbitrary code, bypass security measures, manipulate data, disclose sensitive information, or trigger a denial-of-service condition. The advisory tracks CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55564, CVE-2026-55648.
In CERT-Bund's CSAF data, affected versions are before 3.27.0, and the fixed version is 3.27.0. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX, Windows.
References
- wid.cert-bund.de · wid-sec-w-2026-1933.json technical description
- freerdp.com · 3_27_0-release third party advisory
- github.com · GHSA-5c5v-f78v-h2f6 vendor advisory
- github.com · GHSA-7rp4-66mc-j9vx vendor advisory
- github.com · GHSA-9gxm-3mf5-f5cx vendor advisory
- github.com · GHSA-vx73-w5q6-7jqr vendor advisory
- github.com · GHSA-3mmf-qh4f-frm6 vendor advisory
- access.redhat.com · RHSA-2026:61378 third party advisory
- errata.build.resf.org · RLSA-2026:61379 third party advisory
- errata.build.resf.org · RLSA-2026:61378 third party advisory
- linux.oracle.com · ELSA-2026-61379-0.html third party advisory
- access.redhat.com · RHSA-2026:62571 third party advisory
- errata.build.resf.org · RLSA-2026:62571 third party advisory
- linux.oracle.com · ELSA-2026-61378-0.html third party advisory
- linux.oracle.com · ELSA-2026-62571-0.html third party advisory
- access.redhat.com · RHSA-2026:65855 third party advisory
- access.redhat.com · RHSA-2026:66349 third party advisory
- access.redhat.com · RHSA-2026:66281 third party advisory
- access.redhat.com · RHSA-2026:66282 third party advisory
- access.redhat.com · RHSA-2026:66347 third party advisory
- linux.oracle.com · ELSA-2026-66347-0.html third party advisory