Technology · FreeRDP
FreeRDP vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 66 vulnerabilities in FreeRDP: 0 in the last 7 days and 43 in the last 90 days, 19 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91964, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 43
- Critical, all time
- 19
- Exploited in the wild
- 0
About FreeRDP
FreeRDP is a free remote desktop protocol implementation which allows for connecting to Windows Terminal Services.
Latest FreeRDP vulnerabilities
- CVE-2026-91964: FreeRDP heap buffer overflow in nego_send_negotiation_requesthighCVSS 8.8EPSS 0.6%
- CVE-2026-91963: FreeRDP uninitialized heap memory disclosure in urbdrcmediumCVSS 6.5EPSS 0.6%
- CVE-2026-91962: FreeRDP integer overflow in audin Apple backendsmediumCVSS 6.3EPSS 0.3%
- CVE-2026-91961: FreeRDP denial of service in URBDRC control-transfermediumCVSS 6.5EPSS 0.4%
- CVE-2026-91960: FreeRDP integer overflow in WinPR Stream_EnsureRemainingCapacitymediumCVSS 6.5EPSS 0.5%
- CVE-2026-91959: FreeRDP buffer over-read in RPC gateway parsermediumCVSS 6.5EPSS 0.4%
- CVE-2026-91958: FreeRDP unbounded array indexing in X11 monitor selectionmediumCVSS 6.6EPSS 0.2%
- CVE-2026-91957: FreeRDP use-after-free in smartcard RDPDR device handlerlowCVSS 3.1EPSS 0.4%
- CVE-2026-91956: FreeRDP out-of-bounds read in URBDRC channelmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91955: FreeRDP server denial of service via unvalidated desktop dimensionshighCVSS 7.5EPSS 0.6%
- CVE-2026-91954: FreeRDP null pointer dereference in gdi_surface_bits with NSCodecmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91953: FreeRDP heap buffer overflow in negotiation request routing tokenmediumCVSS 6.5EPSS 0.5%
- CVE-2026-91952: FreeRDP infinite loop denial of service in pool_decode_rectmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91951: FreeRDP out-of-bounds write in urbdrc client channelmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91950: FreeRDP out-of-bounds read in rdpdr_dump_packetmediumCVSS 6.5EPSS 0.4%
- CVE-2026-91949: FreeRDP protocol negotiation bypass in server modecriticalCVSS 9.3EPSS 0.6%
- CVE-2026-91948: FreeRDP out-of-bounds write in static virtual channel handlinghighCVSS 7.5EPSS 0.6%
- CVE-2026-91947: FreeRDP server use-after-free in DRDYNVC parserhighCVSS 7.5EPSS 0.3%
- CVE-2026-91946: FreeRDP RDPGFX ResetGraphics uninitialized memory disclosuremediumCVSS 6.5EPSS 0.5%
- CVE-2026-91945: FreeRDP out-of-bounds read in smartcard response decodermediumCVSS 6.5EPSS 0.6%
- CVE-2026-85090: FreeRDP heap out-of-bounds read in AVC444 chroma plane reconstructionmediumCVSS 5.4EPSS 0.4%
- CVE-2026-85089: FreeRDP uninitialized heap memory leak in Save Session Info PDUmediumCVSS 6.5EPSS 0.5%
- CVE-2026-63652: FreeRDP double-free in audio format handlingmediumCVSS 6.5EPSS 0.6%
- CVE-2026-63633: FreeRDP heap buffer overflow in Opus audio decodingcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-63117: FreeRDP integer division by zero in rdpsnd servermediumCVSS 6.5EPSS 0.5%
Most severe FreeRDP vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-55191: FreeRDP buffer overflow in H.264 AVC444 decodingcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-63633: FreeRDP heap buffer overflow in Opus audio decodingcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-55194: FreeRDP heap buffer overflow in RPC gateway response handlingcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-23530: FreeRDP heap buffer overflow in freerdp_bitmap_decompress_planarcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-23534: FreeRDP heap buffer overflow in ClearCodec bands decode pathcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-23533: FreeRDP heap buffer overflow in ClearCodec decode pathcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-23531: FreeRDP heap buffer overflow in ClearCodeccriticalCVSS 9.8EPSS 0.6%
- CVE-2026-23532: FreeRDP heap buffer overflow in gdi_SurfaceToSurfacecriticalCVSS 9.8EPSS 0.6%
- CVE-2026-23884: FreeRDP use after free in GDI offscreen bitmap deletioncriticalCVSS 9.8EPSS 0.5%
- CVE-2026-23883: FreeRDP use after free in xf_Pointer_NewcriticalCVSS 9.8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 3 | 1 | |
| 27 Jul 2026 | 2 | 1 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 1 | |
| 17 Aug 2026 | 9 | 3 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 20 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/freerdp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "FreeRDP vulnerabilities", https://junglewise.ai/threats/technologies/freerdp, 26 September 2026.