cbcvebase.
CVE-2026-25941
published 2026-02-25

CVE-2026-25941: FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an…

PriorityP343high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.28%
20.5th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfreerdp2< freerdp3 3.23.0+dfsg-1 (forky)freerdp3 3.23.0+dfsg-1 (forky)
debianfreerdp3< freerdp3 3.23.0+dfsg-1 (forky)freerdp3 3.23.0+dfsg-1 (forky)
freerdpfreerdp
freerdpfreerdp
freerdpfreerdp>= 2.0.0 < 2.11.82.11.8
freerdpfreerdp>= 3.0.0 < 3.23.03.23.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.