CVE-2026-55194
published 2026-08-19CVE-2026-55194: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.62%
47.9th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| freerdp | freerdp | < 3.27.0 | 3.27.0 |
| freerdp | freerdp | — | — |
| ubuntu | freerdp3 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FreeRDP up to 3.26.9 RPC Client rpc_client.c rpc_client_recv_fragment heap-based overflow (Nessus ID 342434)
vuldb·2026-09-25·CVSS 9.8
CVE-2026-55194 [CRITICAL] FreeRDP up to 3.26.9 RPC Client rpc_client.c rpc_client_recv_fragment heap-based overflow (Nessus ID 342434)
A vulnerability, which was classified as critical, was found in FreeRDP up to 3.26.9. Affected by this issue is the function rpc_client_recv_fragment of the file libfreerdp/core/gateway/rpc_client.c of the component RPC Client. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is tracked as CVE-2026-55194. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
Red Hat
FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response
vendor_redhat·2026-08-19·CVSS 8.7
CVE-2026-55194 [HIGH] CWE-120 FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response
FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
A flaw was found in FreeRDP. A remote attacker, specifically a malicious TS Gateway, can ex
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-07-20
CVE-2026-33995 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
No detection rules found.
No public exploits indexed.
2026-08-19
Published