Home/CVE/FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can tri
CVE

CVE-2026-269551

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can tri

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., xfreerdp) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The gdi_SurfaceCommand_ClearCodec() handler does not call is_within_surface() to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled cmd-left/cmd-top (and subcodec rectangle offsets) to reach image copy routines that write into surface-data without bounds enforcement.

The OOB write corrupts an adjacent gdiGfxSurface struct's codecs pointer with attacker-controlled pixel data, and corruption of codecs is sufficient to reach an indirect function pointer call (NSC_CONTEXT.decode at nsc.c:500) on a subsequent codec command, full instruction pointer (RIP) control demonstrated in exploitability harness. Users should upgrade to version 3.23.0 to receive a patch.

HIGH · CVSS 8.8 EPSS 0.00537
EPSS exploitation odds0.54% · top 57%
Act now
  • Public exploit or PoC is available
  • CVSS base score ≥ 7.0
Look this up elsewhere - one-click external pivots
How to read a CVE - triage first, then detect and patch
This page is every public fact about CVE-2026-26955, cross-linked. Its job is to answer one question fast - does this need my attention now? - and then hand you the two things you do about it. Here is how an analyst reads it.
Triage: should I act now? Four signals, and they are not interchangeable:
CVSSseverity - how bad it is IF exploited, 0-10. A high CVSS alone is not urgency; a flaw can be a perfect 10 and never actually be attacked. EPSSprobability - a model’s estimate of the chance it is exploited in the next 30 days, 0-1. This is the “will it actually happen” signal. CISA KEVconfirmed - it is being exploited in the wild right now. The strongest signal on the page; KEV beats any score. Weaponisedavailability - public exploits / PoCs, and especially Metasploit modules rated Excellent / Great. Reliable, packaged exploit code means low-skill attackers can use it today.
How they combine: KEV, or a dependable Metasploit module, means patch now regardless of CVSS. High CVSS + low EPSS + no exploit is real but not an emergency - schedule it. Low CVSS but KEV-listed still gets patched now. The verdict above already weighed these for you; this is how it got there.
Then what - two workflows:
Detectwhen you cannot patch today, follow this CVE to the ATT&CK techniques it enables, then Build a SIEM detection (the green button) - author a rule, test it in Atomic, deploy it. That buys visibility while the patch waits. PatchAffected products / packages tell you if you are exposed; Fixed versions by distribution and Vendor advisories give the exact version that closes it.
Reading order for the panels below: verdict + badges, then Public exploits / Metasploit (is it weaponised), then ATT&CK techniques + Sigma / IDS rules (can I detect it), then Affected products / packages + Fixed versions (am I exposed, what patches it), then Threat actors / IOCs (who uses it), then Scoring & timeline / references (the evidence).

Exploitation evidence

1 of 7 sources
Corroboration score 8/100 · emerging. This counts how many independent sources have exploitation evidence, and separates two different things: confirmed in-the-wild use (CISA KEV, Microsoft MSRC, ransomware activity) from exploit / PoC availability (Metasploit, ExploitDB, Nuclei, public PoCs). A template or PoC existing means an attack is possible and easy - it is not, on its own, proof the CVE is being exploited in the wild.
Exploit / PoC available
public PoC

Exploitation momentum

29 days of EPSS
dormant
Flat and low - no real exploitation pressure. This reads the direction and speed of EPSS over time, which can move before EPSS itself peaks or before CISA lists it.
Window

Severity & exploitation scoring

View on NVD →
CVSS base score
8.8
HIGHCVSS v3.1 · [email protected]
EPSS exploitation probability
0.54%
Top 57%odds of exploitation in the next 30 days
CVSS metric silhouette
VectorComplexityPrivilegesInteractionScopeConfidentialityIntegrityAvailability
shape grows toward worst-case
SSVC triage · cisa-vulnrichment
Exploitation
poc
Automatable
no
Tech impact
total
CVSS vector breakdown
Exploitability - how they get in
Attack Vector
Network Adjacent Local Physical
Attack Complexity
Low High
Privileges Required
None Low High
User Interaction
None Required
Scope
Unchanged Changed
Impact - what breaks
Confidentiality
None Low High
Integrity
None Low High
Availability
None Low High
VECTORCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Lifecycle
  1. 25 Feb 2026Published to NVD
  2. 15 Jul 2026Last modified
Every entry is a recorded date - NVD publish/modify, CISA KEV add, public exploit disclosure. No inferred events.
Attack path
Full kill chain

Public Exploits & PoCs

1
These PoC and exploit links come from public sources and are not verified to be safe or functional. Review the code before running anything, and treat unverified entries as untrusted. Signed-in users mark whether it works, rate 1-10, and can report malware with a required reason that becomes a public comment.
poc Public PoC (nvd-reference) date unknown
Vote & rate
Report or claim
⚠ Report this PoC

Becomes a public comment attributed as First L. (never full last name). Don't include private info. Rate-limited: 5/hour.

Works? no reports yet
Rating -

ATT&CK techniques

2

Techniques this CVE enables. Pills with a solid outline are high confidence - named directly in ATT&CK or Nuclei, or human-curated by CTID; the rest are inferred from the weakness type using MITRE's CVE Mapping Methodology and the CWE → CAPEC chain. Broad, generic-weakness guesses are filtered out. A small marks a technique that N independent sources agree on.

▤ Build a SIEM detection for these techniques

CAPEC attack patterns

2

Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.

Weakness Classification

Affected Products & Versions

1
freerdp< 3.23.0

Affected Packages

16
Language-ecosystem packages (from OSV) tied to this CVE, with the version that fixes it - the dependency-level detail NVD doesn’t carry.
AlmaLinux:10 freerdp fixed in 2:3.10.3-5.el10_1.3
AlmaLinux:10 freerdp-devel fixed in 2:3.10.3-5.el10_1.3
AlmaLinux:10 freerdp-libs fixed in 2:3.10.3-5.el10_1.3
AlmaLinux:10 freerdp-server fixed in 2:3.10.3-5.el10_1.3
AlmaLinux:10 libwinpr fixed in 2:3.10.3-5.el10_1.3
AlmaLinux:10 libwinpr-devel fixed in 2:3.10.3-5.el10_1.3
AlmaLinux:8 freerdp fixed in 2:2.11.7-4.el8_10
AlmaLinux:8 freerdp-devel fixed in 2:2.11.7-4.el8_10
AlmaLinux:8 freerdp-libs fixed in 2:2.11.7-4.el8_10
AlmaLinux:8 libwinpr fixed in 2:2.11.7-4.el8_10
AlmaLinux:8 libwinpr-devel fixed in 2:2.11.7-4.el8_10
AlmaLinux:9 freerdp fixed in 2:2.11.7-1.el9_7.3
AlmaLinux:9 freerdp-devel fixed in 2:2.11.7-1.el9_7.3
AlmaLinux:9 freerdp-libs fixed in 2:2.11.7-1.el9_7.3
AlmaLinux:9 libwinpr fixed in 2:2.11.7-1.el9_7.3
AlmaLinux:9 libwinpr-devel fixed in 2:2.11.7-1.el9_7.3
📦

Fixed versions by distribution

40
The package version that resolves this CVE on each Linux distribution, from the vendor’s published security data. fixed in shows a patched version exists; open means the package is listed as affected with no fix yet.
alpine edgefreerdp fixed in 3.23.0-r0
oracle allfreerdp open
oracle allfreerdp-devel fixed in 2:3.10.3-5.el10_1.3
oracle allfreerdp-libs open
oracle allfreerdp-server open
oracle alllibwinpr fixed in 2:3.10.3-5.el10_1.3
oracle alllibwinpr-devel open
rhel 8freerdp fixed in 2:2.11.7-4.el8_10
rhel 8freerdp-devel open
rhel 8freerdp-libs open
rhel 8libwinpr open
rhel 8libwinpr-devel open
rhel 9freerdp open
rhel 9freerdp-devel fixed in 2:2.11.7-1.el9_7.3
rhel 9freerdp-libs open
rhel 9libwinpr open
rhel 9libwinpr-devel fixed in 2:2.11.7-1.el9_7.3
suse sle15freerdp fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp-devel fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp-proxy fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp-proxy-plugins fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp-sdl fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp-server fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp-wayland fixed in 0:3.10.3-150700.3.9.1
suse sle15freerdp2 fixed in 0:2.11.7-150700.3.14.1
suse sle15freerdp2-devel fixed in 0:2.11.7-150700.3.14.1
suse sle15freerdp2-proxy fixed in 0:2.11.7-150700.3.14.1
suse sle15freerdp2-server fixed in 0:2.11.7-150700.3.14.1
suse sle15libfreerdp-server-proxy3-3 fixed in 0:3.10.3-150700.3.9.1
suse sle15libfreerdp2 fixed in 0:2.4.0-150400.3.47.1
suse sle15libfreerdp2-2 fixed in 0:2.11.7-150700.3.14.1
suse sle15libfreerdp3-3 fixed in 0:3.10.3-150700.3.9.1
suse sle15librdtk0-0 fixed in 0:3.10.3-150700.3.9.1
suse sle15libuwac0-0 fixed in 0:3.10.3-150700.3.9.1
suse sle15libwinpr2 fixed in 0:2.4.0-150400.3.47.1
suse sle15libwinpr2-2 fixed in 0:2.11.7-150700.3.14.1
suse sle15libwinpr3-3 fixed in 0:3.10.3-150700.3.9.1
suse sle15uwac0-0-devel fixed in 0:2.11.2-150600.4.18.1
suse sle15winpr-devel fixed in 0:3.10.3-150700.3.9.1
suse sle15winpr2-devel fixed in 0:2.11.7-150700.3.14.1

Vendor Advisories

29
suse-csafrhsa-2026_6385
rhsaRHSA-2026:19033Important
suse-csafrhsa-2026_6004
suse-csafrhsa-2026_6005
suse-csafrhsa-2026_5939
rhsaRHSA-2026:5936Important
rhsaRHSA-2026:6712Important
rhsaRHSA-2026:6616Important
rhsaRHSA-2026:5939Important
rhsaRHSA-2026:6395Important
rhsaRHSA-2026:6384Important
rhsaRHSA-2026:7292Important
rhsaRHSA-2026:6005Important
rhsaRHSA-2026:6665Important
rhsaRHSA-2026:6764Important
rhsaRHSA-2026:6004Important
rhsaRHSA-2026:6396Important
rhsaRHSA-2026:6385Important