
CVE-2026-25954 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_size` dereferences a freed `xfAppWindow` pointer … https://www.cve.org/CVERecord?id=CVE-2026-25954
Post summary
The CVE-2026-25954 vulnerability in FreeRDP involves a use‑after‑free in the `xf_rail_server_local_move_size` function before version 3.23.0.

