
🚨 HIGH SEVERITY: CVE-2026-55193 (CVSS 8.8) FreeRDP clients using TS Gateway vulnerable to heap buffer overflow. Malicious gateway can trigger crash or RCE. ✅ Update to v3.27.0 immediately #CVE #Vulnerability #PatchNow https://t.co/QobHDuBlqZ
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

🚨 HIGH SEVERITY: CVE-2026-55193 (CVSS 8.8) FreeRDP clients using TS Gateway vulnerable to heap buffer overflow. Malicious gateway can trigger crash or RCE. ✅ Update to v3.27.0 immediately #CVE #Vulnerability #PatchNow https://t.co/QobHDuBlqZ
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | freerdp | freerdp | - | - | - |