
🔴 CVE-2026-25953 - Critical FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread ob... https://www.thehackerwire.com/vulnerability/CVE-2026-25953/ https://t.co/OHnpjVaaxr
Post summary
The post highlights a critical use‑after‑free flaw in FreeRDP prior to v3.23.0, where the RDPGFX DVC thread can read from a freed object, and provides a link to a detailed write‑up.


