
CVE-2026-67299 FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /a… https://www.cve.org/CVERecord?id=CVE-2026-67299
Post summary
The passage details a client‑side heap use‑after‑free flaw in FreeRDP ≤3.29.0, but offers no PoC, exploit code, patch, or evidence of active exploitation.
