Exploitation ongoing with high activity in latest observed window (3 mentions)
Immediate actions
Patch freerdp freerdp systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. This may affect all client and server implementations using `FreeRDP`. For practical exploitation this will only work on 32bit systems where the available physical memory is `>= SIZE_MAX`. Version 3.23.0 contains a patch. No known workarounds are available.
CVE-2026-27951 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the function `Stream_EnsureCapacity` can create an endless blocking loop. Th… https://www.cve.org/CVERecord?id=CVE-2026-27951
Post summary
The CVE-2026-27951 vulnerability in FreeRDP involves an endless blocking loop in the `Stream_EnsureCapacity` function before version 3.23.0, but no PoC, exploit, or patch details are provided.
Today's Top Cybersecurity News – February 26, 2026
1. CVE-2026-3057: SQL Injection in pearProjectApi Backend Task.php dateTotalForProject
A remote SQL injection vulnerability exists in the dateTotalForProject function of pearProjectApi up to version 2.8.10, allowing attackers to manipulate the projectCode argument. The exploit is publicly available, increasing the risk of unauthorized data access or modification.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2026-3057
2. Critical Authentication Bypass and Privilege Escalation Vulnerabilities in Cisco Catalyst SD-WAN
Multiple critical vulnerabilities in Cisco Catalyst SD-WAN products allow unauthenticated remote attackers to bypass authentication, escalate privileges to admin or root, and take full control of affected devices. Notably, CVE-2026-20127 has been actively exploited in zero-day attacks since 2023, enabling attackers to compromise controllers and insert rogue peers into networks. Users are urged to identify vulnerable devices, collect forensic data, update to patched versions, and conduct threat hunting.
Sources: Bleepingcomputer, Cvefeed, Cyberscoop, Feedburner, Gbhackers, Kyberturvallisuuskeskus, Rapid7, Talosintelligence, Therecord
https://www.kyberturvallisuuskeskus.fi/fi/kriittisia-haavoittuvuuksia-cisco-catalyst-sd-wan-tuotteissa
3. Multiple Critical and High Vulnerabilities Found in Binardat 10G08-0800GSM Network Switch
A series of critical and high-severity vulnerabilities have been identified in Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209. These include hard-coded credentials, predictable session IDs, plaintext password exposure, weak encryption, and command injection, exposing devices to unauthorized access, credential compromise, and remote code execution. Medium-severity issues such as missing login rate limiting, CSRF, and XSS further increase the attack surface.
Sources: Bleepingcomputer, Cvefeed, Securityweek
https://cvefeed.io/vuln/detail/CVE-2026-27521
4. Multiple Vulnerabilities Disclosed Including Critical Path Traversal in Local Path Provisioner
Several security vulnerabilities were disclosed affecting various platforms including Octopus Deploy, Red Hat Developer Hub, openSUSE, Udisks, Rancher CLI, and Local Path Provisioner. Notably, a critical path traversal vulnerability in Local Path Provisioner allows attackers to overwrite sensitive files, while other issues range from denial of service to unauthorized access of encryption metadata.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2026-0704
5. Multiple Critical Vulnerabilities in FreeRDP Affecting Versions Prior to 3.23.0
FreeRDP versions before 3.23.0 contain multiple severe vulnerabilities including heap-use-after-free, out-of-bounds writes, integer overflow, and denial-of-service flaws. These issues can lead to client or server crashes, memory corruption, and potential remote code execution, especially when interacting with malicious RDP servers or crafted data. A patch addressing all these vulnerabilities is available in version 3.23.0.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2026-27951
Stay sharp. Stay secure.
#NerdieNews#InfoSec#CyberSecurity#TechNews#DataSecurity#CyberThreats
Post summary
The article reports several critical CVEs, noting active exploitation of Cisco SD‑WAN CVE‑2026‑20127, publicly available exploits for other vulnerabilities, and available patches for affected software.
CVE-2026-27951
FreeRDP Denial of Service Vulnerability in Stream_EnsureCapacity Function Before 3.23.0
https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27951
Post summary
A Denial of Service vulnerability in FreeRDP's Stream_EnsureCapacity function before version 3.23.0 has been disclosed.