{"schema_version":1,"title":"FreeRDP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 66 vulnerabilities in FreeRDP: 0 in the last 7 days and 43 in the last 90 days, 19 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91964, was published on 15 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/freerdp","json_url":"https://junglewise.ai/threats/vendors/freerdp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/freerdp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":21,"all_time":66,"critical":19,"exploited":0,"last_7_days":0,"last_30_days":22,"last_90_days":43,"last_365_days":66},"latest":[{"cve":"CVE-2026-91964","cvss":8.8,"epss":0.006,"slug":"cve-2026-91964-freerdp-heap-buffer-overflow-in-nego-send-negotiation-request","title":"FreeRDP heap buffer overflow in nego_send_negotiation_request","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:52.48+00:00","url":"https://junglewise.ai/threats/cve-2026-91964-freerdp-heap-buffer-overflow-in-nego-send-negotiation-request"},{"cve":"CVE-2026-91963","cvss":6.5,"epss":0.006,"slug":"cve-2026-91963-freerdp-uninitialized-heap-memory-disclosure-in-urbdrc","title":"FreeRDP uninitialized heap memory disclosure in urbdrc","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:51.907+00:00","url":"https://junglewise.ai/threats/cve-2026-91963-freerdp-uninitialized-heap-memory-disclosure-in-urbdrc"},{"cve":"CVE-2026-91962","cvss":6.3,"epss":0.0026,"slug":"cve-2026-91962-freerdp-integer-overflow-in-audin-apple-backends","title":"FreeRDP integer overflow in audin Apple backends","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:51.763+00:00","url":"https://junglewise.ai/threats/cve-2026-91962-freerdp-integer-overflow-in-audin-apple-backends"},{"cve":"CVE-2026-91961","cvss":6.5,"epss":0.0037,"slug":"cve-2026-91961-freerdp-denial-of-service-in-urbdrc-control-transfer","title":"FreeRDP denial of service in URBDRC control-transfer","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:51.613+00:00","url":"https://junglewise.ai/threats/cve-2026-91961-freerdp-denial-of-service-in-urbdrc-control-transfer"},{"cve":"CVE-2026-91960","cvss":6.5,"epss":0.0046,"slug":"cve-2026-91960-freerdp-integer-overflow-in-winpr-stream-ensureremainingcapacity","title":"FreeRDP integer overflow in WinPR Stream_EnsureRemainingCapacity","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:51.07+00:00","url":"https://junglewise.ai/threats/cve-2026-91960-freerdp-integer-overflow-in-winpr-stream-ensureremainingcapacity"},{"cve":"CVE-2026-91959","cvss":6.5,"epss":0.0038,"slug":"cve-2026-91959-freerdp-buffer-over-read-in-rpc-gateway-parser","title":"FreeRDP buffer over-read in RPC gateway parser","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:50.93+00:00","url":"https://junglewise.ai/threats/cve-2026-91959-freerdp-buffer-over-read-in-rpc-gateway-parser"},{"cve":"CVE-2026-91958","cvss":6.6,"epss":0.0016,"slug":"cve-2026-91958-freerdp-unbounded-array-indexing-in-x11-monitor-selection","title":"FreeRDP unbounded array indexing in X11 monitor selection","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:50.787+00:00","url":"https://junglewise.ai/threats/cve-2026-91958-freerdp-unbounded-array-indexing-in-x11-monitor-selection"},{"cve":"CVE-2026-91957","cvss":3.1,"epss":0.0036,"slug":"cve-2026-91957-freerdp-use-after-free-in-smartcard-rdpdr-device-handler","title":"FreeRDP use-after-free in smartcard RDPDR device handler","severity":"low","exploited":false,"published_at":"2026-09-15T16:17:50.647+00:00","url":"https://junglewise.ai/threats/cve-2026-91957-freerdp-use-after-free-in-smartcard-rdpdr-device-handler"},{"cve":"CVE-2026-91956","cvss":6.5,"epss":0.0038,"slug":"cve-2026-91956-freerdp-out-of-bounds-read-in-urbdrc-channel","title":"FreeRDP out-of-bounds read in URBDRC channel","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:50.5+00:00","url":"https://junglewise.ai/threats/cve-2026-91956-freerdp-out-of-bounds-read-in-urbdrc-channel"},{"cve":"CVE-2026-91955","cvss":7.5,"epss":0.0057,"slug":"cve-2026-91955-freerdp-server-denial-of-service-via-unvalidated-desktop","title":"FreeRDP server denial of service via unvalidated desktop dimensions","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:49.963+00:00","url":"https://junglewise.ai/threats/cve-2026-91955-freerdp-server-denial-of-service-via-unvalidated-desktop"},{"cve":"CVE-2026-91954","cvss":6.5,"epss":0.0038,"slug":"cve-2026-91954-freerdp-null-pointer-dereference-in-gdi-surface-bits-with-nscodec","title":"FreeRDP null pointer dereference in gdi_surface_bits with NSCodec","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:49.807+00:00","url":"https://junglewise.ai/threats/cve-2026-91954-freerdp-null-pointer-dereference-in-gdi-surface-bits-with-nscodec"},{"cve":"CVE-2026-91953","cvss":6.5,"epss":0.0046,"slug":"cve-2026-91953-freerdp-heap-buffer-overflow-in-negotiation-request-routing-token","title":"FreeRDP heap buffer overflow in negotiation request routing token","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:49.657+00:00","url":"https://junglewise.ai/threats/cve-2026-91953-freerdp-heap-buffer-overflow-in-negotiation-request-routing-token"},{"cve":"CVE-2026-91952","cvss":6.5,"epss":0.0039,"slug":"cve-2026-91952-freerdp-infinite-loop-denial-of-service-in-pool-decode-rect","title":"FreeRDP infinite loop denial of service in pool_decode_rect","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:49.49+00:00","url":"https://junglewise.ai/threats/cve-2026-91952-freerdp-infinite-loop-denial-of-service-in-pool-decode-rect"},{"cve":"CVE-2026-91951","cvss":6.5,"epss":0.0038,"slug":"cve-2026-91951-freerdp-out-of-bounds-write-in-urbdrc-client-channel","title":"FreeRDP out-of-bounds write in urbdrc client channel","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:49.34+00:00","url":"https://junglewise.ai/threats/cve-2026-91951-freerdp-out-of-bounds-write-in-urbdrc-client-channel"},{"cve":"CVE-2026-91950","cvss":6.5,"epss":0.004,"slug":"cve-2026-91950-freerdp-out-of-bounds-read-in-rdpdr-dump-packet","title":"FreeRDP out-of-bounds read in rdpdr_dump_packet","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:48.8+00:00","url":"https://junglewise.ai/threats/cve-2026-91950-freerdp-out-of-bounds-read-in-rdpdr-dump-packet"},{"cve":"CVE-2026-91949","cvss":9.3,"epss":0.0056,"slug":"cve-2026-91949-freerdp-protocol-negotiation-bypass-in-server-mode","title":"FreeRDP protocol negotiation bypass in server mode","severity":"critical","exploited":false,"published_at":"2026-09-15T16:17:48.653+00:00","url":"https://junglewise.ai/threats/cve-2026-91949-freerdp-protocol-negotiation-bypass-in-server-mode"},{"cve":"CVE-2026-91948","cvss":7.5,"epss":0.0059,"slug":"cve-2026-91948-freerdp-out-of-bounds-write-in-static-virtual-channel-handling","title":"FreeRDP out-of-bounds write in static virtual channel handling","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:48.503+00:00","url":"https://junglewise.ai/threats/cve-2026-91948-freerdp-out-of-bounds-write-in-static-virtual-channel-handling"},{"cve":"CVE-2026-91947","cvss":7.5,"epss":0.0032,"slug":"cve-2026-91947-freerdp-server-use-after-free-in-drdynvc-parser","title":"FreeRDP server use-after-free in DRDYNVC parser","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:48.353+00:00","url":"https://junglewise.ai/threats/cve-2026-91947-freerdp-server-use-after-free-in-drdynvc-parser"},{"cve":"CVE-2026-91946","cvss":6.5,"epss":0.0046,"slug":"cve-2026-91946-freerdp-rdpgfx-resetgraphics-uninitialized-memory-disclosure","title":"FreeRDP RDPGFX ResetGraphics uninitialized memory disclosure","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:47.99+00:00","url":"https://junglewise.ai/threats/cve-2026-91946-freerdp-rdpgfx-resetgraphics-uninitialized-memory-disclosure"},{"cve":"CVE-2026-91945","cvss":6.5,"epss":0.0058,"slug":"cve-2026-91945-freerdp-out-of-bounds-read-in-smartcard-response-decoder","title":"FreeRDP out-of-bounds read in smartcard response decoder","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:46.657+00:00","url":"https://junglewise.ai/threats/cve-2026-91945-freerdp-out-of-bounds-read-in-smartcard-response-decoder"},{"cve":"CVE-2026-85090","cvss":5.4,"epss":0.0043,"slug":"cve-2026-85090-freerdp-heap-out-of-bounds-read-in-avc444-chroma-plane","title":"FreeRDP heap out-of-bounds read in AVC444 chroma plane reconstruction","severity":"medium","exploited":false,"published_at":"2026-09-03T13:06:20.43+00:00","url":"https://junglewise.ai/threats/cve-2026-85090-freerdp-heap-out-of-bounds-read-in-avc444-chroma-plane"},{"cve":"CVE-2026-85089","cvss":6.5,"epss":0.0055,"slug":"cve-2026-85089-freerdp-uninitialized-heap-memory-leak-in-save-session-info-pdu","title":"FreeRDP uninitialized heap memory leak in Save Session Info PDU","severity":"medium","exploited":false,"published_at":"2026-09-03T13:06:20.277+00:00","url":"https://junglewise.ai/threats/cve-2026-85089-freerdp-uninitialized-heap-memory-leak-in-save-session-info-pdu"},{"cve":"CVE-2026-63652","cvss":6.5,"epss":0.0058,"slug":"cve-2026-63652-freerdp-double-free-in-audio-format-handling","title":"FreeRDP double-free in audio format handling","severity":"medium","exploited":false,"published_at":"2026-08-19T18:17:10.167+00:00","url":"https://junglewise.ai/threats/cve-2026-63652-freerdp-double-free-in-audio-format-handling"},{"cve":"CVE-2026-63633","cvss":9.8,"epss":0.0064,"slug":"cve-2026-63633-freerdp-heap-buffer-overflow-in-opus-audio-decoding","title":"FreeRDP heap buffer overflow in Opus audio decoding","severity":"critical","exploited":false,"published_at":"2026-08-19T18:17:10.017+00:00","url":"https://junglewise.ai/threats/cve-2026-63633-freerdp-heap-buffer-overflow-in-opus-audio-decoding"},{"cve":"CVE-2026-63117","cvss":6.5,"epss":0.0055,"slug":"cve-2026-63117-freerdp-integer-division-by-zero-in-rdpsnd-server","title":"FreeRDP integer division by zero in rdpsnd server","severity":"medium","exploited":false,"published_at":"2026-08-19T18:17:08.43+00:00","url":"https://junglewise.ai/threats/cve-2026-63117-freerdp-integer-division-by-zero-in-rdpsnd-server"}],"vendor":{"hub":true,"name":"FreeRDP","slug":"freerdp","homepage":"https://www.freerdp.com/","description":"FreeRDP is an open source project providing a free implementation of the Remote Desktop Protocol (RDP).","url":"https://junglewise.ai/threats/vendors/freerdp"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":3,"exploited":0,"vulnerabilities":9},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":20},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-55191","cvss":9.8,"epss":0.0083,"slug":"cve-2026-55191-freerdp-buffer-overflow-in-h-264-avc444-decoding","title":"FreeRDP buffer overflow in H.264 AVC444 decoding","severity":"critical","exploited":false,"published_at":"2026-08-19T18:16:44.427+00:00","url":"https://junglewise.ai/threats/cve-2026-55191-freerdp-buffer-overflow-in-h-264-avc444-decoding"},{"cve":"CVE-2026-63633","cvss":9.8,"epss":0.0064,"slug":"cve-2026-63633-freerdp-heap-buffer-overflow-in-opus-audio-decoding","title":"FreeRDP heap buffer overflow in Opus audio decoding","severity":"critical","exploited":false,"published_at":"2026-08-19T18:17:10.017+00:00","url":"https://junglewise.ai/threats/cve-2026-63633-freerdp-heap-buffer-overflow-in-opus-audio-decoding"},{"cve":"CVE-2026-55194","cvss":9.8,"epss":0.0064,"slug":"cve-2026-55194-freerdp-heap-buffer-overflow-in-rpc-gateway-response-handling","title":"FreeRDP heap buffer overflow in RPC gateway response handling","severity":"critical","exploited":false,"published_at":"2026-08-19T18:16:44.857+00:00","url":"https://junglewise.ai/threats/cve-2026-55194-freerdp-heap-buffer-overflow-in-rpc-gateway-response-handling"},{"cve":"CVE-2026-23530","cvss":9.8,"epss":0.006,"slug":"cve-2026-23530-freerdp-heap-buffer-overflow-in-freerdp-bitmap-decompress-planar","title":"FreeRDP heap buffer overflow in freerdp_bitmap_decompress_planar","severity":"critical","exploited":false,"published_at":"2026-01-19T17:15:50.747+00:00","url":"https://junglewise.ai/threats/cve-2026-23530-freerdp-heap-buffer-overflow-in-freerdp-bitmap-decompress-planar"},{"cve":"CVE-2026-23534","cvss":9.8,"epss":0.0059,"slug":"cve-2026-23534-freerdp-heap-buffer-overflow-in-clearcodec-bands-decode-path","title":"FreeRDP heap buffer overflow in ClearCodec bands decode path","severity":"critical","exploited":false,"published_at":"2026-01-19T18:16:05.307+00:00","url":"https://junglewise.ai/threats/cve-2026-23534-freerdp-heap-buffer-overflow-in-clearcodec-bands-decode-path"},{"cve":"CVE-2026-23533","cvss":9.8,"epss":0.0059,"slug":"cve-2026-23533-freerdp-heap-buffer-overflow-in-clearcodec-decode-path","title":"FreeRDP heap buffer overflow in ClearCodec decode path","severity":"critical","exploited":false,"published_at":"2026-01-19T18:16:05.17+00:00","url":"https://junglewise.ai/threats/cve-2026-23533-freerdp-heap-buffer-overflow-in-clearcodec-decode-path"},{"cve":"CVE-2026-23531","cvss":9.8,"epss":0.0058,"slug":"cve-2026-23531-freerdp-heap-buffer-overflow-in-clearcodec","title":"FreeRDP heap buffer overflow in ClearCodec","severity":"critical","exploited":false,"published_at":"2026-01-19T17:15:50.897+00:00","url":"https://junglewise.ai/threats/cve-2026-23531-freerdp-heap-buffer-overflow-in-clearcodec"},{"cve":"CVE-2026-23532","cvss":9.8,"epss":0.0057,"slug":"cve-2026-23532-freerdp-heap-buffer-overflow-in-gdi-surfacetosurface","title":"FreeRDP heap buffer overflow in gdi_SurfaceToSurface","severity":"critical","exploited":false,"published_at":"2026-01-19T17:15:51.04+00:00","url":"https://junglewise.ai/threats/cve-2026-23532-freerdp-heap-buffer-overflow-in-gdi-surfacetosurface"},{"cve":"CVE-2026-23884","cvss":9.8,"epss":0.0054,"slug":"cve-2026-23884-freerdp-use-after-free-in-gdi-offscreen-bitmap-deletion","title":"FreeRDP use after free in GDI offscreen bitmap deletion","severity":"critical","exploited":false,"published_at":"2026-01-19T18:16:06.43+00:00","url":"https://junglewise.ai/threats/cve-2026-23884-freerdp-use-after-free-in-gdi-offscreen-bitmap-deletion"},{"cve":"CVE-2026-23883","cvss":9.8,"epss":0.0054,"slug":"cve-2026-23883-freerdp-use-after-free-in-xf-pointer-new","title":"FreeRDP use after free in xf_Pointer_New","severity":"critical","exploited":false,"published_at":"2026-01-19T18:16:06.297+00:00","url":"https://junglewise.ai/threats/cve-2026-23883-freerdp-use-after-free-in-xf-pointer-new"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"FreeRDP","slug":"freerdp","vulnerabilities":66,"url":"https://junglewise.ai/threats/technologies/freerdp"}]}