CVE-2026-27950Disclosure(freerdp / freerdp)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch freerdp freerdp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplete. While the vulnerable execution flow referenced in the advisory exists in the SDL2 implementation, the fix appears to have been applied only to the SDL3 code path. In the SDL2 implementation, the pointer is not nulled after free. This creates a situation where the advisory suggests the vulnerability is fully resolved, while builds or environments still using SDL2 may retain the vulnerable logic. A complete fix is available in version 3.23.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-26: 2Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-26: 202-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Patch

    CVE-2026-27950 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after-free described in CVE-2026-24680 is incomplet… https://www.cve.org/CVERecord?id=CVE-2026-27950

    Post summary

    The post highlights that FreeRDP’s fix for CVE-2026-24680 is incomplete before version 3.23.0, providing technical details about a heap-use-after-free vulnerability and patch status.

    00000112
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27950 Incomplete Heap-Use-After-Free Vulnerability in FreeRDP SDL2 Implementation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27950

    Post summary

    A new heap-use-after-free vulnerability (CVE-2026-27950) has been disclosed in the FreeRDP SDL2 implementation, with no PoC, exploit, or patch details provided.

    0000060
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more