CVE-2026-24679Disclosure(freerdp / freerdp)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusb_udev_select_interface. This vulnerability is fixed in 3.22.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-11: 102-0902-1002-11
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure2
2026-02-111
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24679 FreeRDP URBDRC Client Out-of-Bounds Read Vulnerability Before 3.22.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24679

    Post summary

    The text announces a FreeRDP URBDRC Client out-of-bounds read vulnerability affecting versions prior to 3.22.0.

    0001156
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24679 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bo… https://www.cve.org/CVERecord?id=CVE-2026-24679

    Post summary

    The text cites CVE‑2026‑24679 affecting FreeRDP’s URBDRC client, describing an array index vulnerability prior to v3.22.0, but it does not mention patches, PoCs, or active exploitation.

    00010163
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical out-of-bounds read (CVE-2026-24679) affects `FreeRDP` clients prior to 3.22.0. This flaw can lead to information disclosure or client crashes when connecting to a malicious RDP server. #FreeRDP #CyberSecurity #Vulnerability https://www.pulsepatch.io/posts/cve-2026-24679-freerdp2-out-of-bounds-read

    Post summary

    The post discloses a critical out‑of‑bounds read in FreeRDP clients before version 3.22.0 that could lead to information disclosure or crashes, without providing PoC or exploit details.

    0000041
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-24679 - Critical FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing ... https://www.thehackerwire.com/vulnerability/CVE-2026-24679/ https://t.co/vIV7HhCEZV

    Post summary

    A critical vulnerability in FreeRDP’s URBDRC client allows unchecked array indexing, potentially enabling exploitation; no PoC, exploit code, or active exploitation is reported, and no patch is referenced.

    0000066
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more