
🔴 CVE-2026-25952 - Critical FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` ... https://www.thehackerwire.com/vulnerability/CVE-2026-25952/ https://t.co/j5biTUccDK
Post summary
The post announces CVE‑2026‑25952 as a critical vulnerability in FreeRDP, detailing a use‑after‑free in `xf_SetWindowMinMaxInfo` before version 3.23.0.


