CVE-2026-22858 is a critical global-buffer-overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol, affecting versions prior to 3.20.1. This flaw stems from implementation-defined char signedness on Arm/AArch64 builds, allowing non-ASCII bytes to bypass range checks and cause out-of-bounds access during Base64 decoding. With a CVSS score of 9.1 (CRITICAL), it presents a high-impact, unauthenticated remote attack vector (AV:N/AC:L/PR:N/UI:N) leading to potential compromise of confidentiality and availability (C:H/A:H). While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion with 11 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.20.1CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.