
CVE-2026-40254 FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/dr… https://www.cve.org/CVERecord?id=CVE-2026-40254
Post summary
CVE-2026-40254 reveals an off‑by‑one path traversal flaw in FreeRDP versions below 3.25.0; no PoC, exploit, or active exploitation is reported, nor is any patch or mitigation mentioned.
