CVE-2026-25955Disclosure(freerdp / freerdp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surface buffer, because `gdi_DeleteSurface` frees `surface->data` without invalidating the `appWindow->image` that aliases it. Version 3.23.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-01: 102-2602-2703-01
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure1General1
2026-02-271
Disclosure1
2026-03-011
Disclosure1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25955 - Critical FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed ... https://www.thehackerwire.com/vulnerability/CVE-2026-25955/ https://t.co/1yjt1NGBSD

    Post summary

    A critical FreeRDP vulnerability (CVE‑2026‑25955) involves a use‑after‑free bug in XImage handling; the text provides technical detail but no evidence of exploitation, PoC, or patch.

    0000137
    119 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25955 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointe… https://www.cve.org/CVERecord?id=CVE-2026-25955

    Post summary

    The post references CVE‑2026‑25955 for FreeRDP, noting a function that reuses a cached XImage, but provides no further details on exploitation, patches, or PoC.

    00001120
    56.6K followersView on X
  • CVEDatabase.com@cvedatabase
    Disclosure

    New Remote Code Execution Vulnerability for FreeRDP. More info here: CVE-CVE-2026-25955 | MEDIUM Severity | http://CVEDatabase.com - https://cvedatabase.com/cve/CVE-2026-25955

    Post summary

    A new medium‑severity RCE vulnerability in FreeRDP (CVE‑2026‑25955) has been disclosed, with basic details provided but no PoC, exploit, or patch information.

    0000046
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25955 Use-After-Free Vulnerability in FreeRDP Prior to Version 3.23.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25955

    Post summary

    A use‑after‑free vulnerability (CVE‑2026‑25955) exists in FreeRDP versions before 3.23.0, as reported on Vulmon.

    0000052
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more