Remote Desktop Protocol Vulnerability in FreeRDP by FreeRDP
CVE-2026-55193

8.7HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55193?

FreeRDP, a free implementation of the Remote Desktop Protocol, has a vulnerability that allows attackers to manipulate the max_xmit_frag value in a way that could lead to a buffer overflow. Prior to version 3.27.0, FreeRDP clients did not properly bound this value, allowing a malicious gateway to send a fragment up to 65535 bytes. This could cause clients to crash and potentially allow for code execution via heap corruption. Users are advised to upgrade to version 3.27.0 or later to mitigate this risk.

Affected Version(s)

FreeRDP < 3.27.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.