Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23533

37
FAUCET Score

CVE-2026-23533 is a critical client-side heap buffer overflow vulnerability affecting FreeRDP versions prior to 3.21.0, a free implementation of the Remote Desktop Protocol. A malicious server can exploit this flaw during the RDPGFX ClearCodec decode path, leading to out-of-bounds writes and causing a denial of service (DoS) or potentially remote code execution due to heap corruption. With a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 12 mentions and 2 media articles.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.21.0CPE matchmatch criteria
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 12th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: freerdp-2:2.11.7-1.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: freerdp-2:3.10.3-5.el10_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: freerdp-2:3.10.3-3.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: freerdp-0:2.1.1-5.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: freerdp-2:2.11.7-2.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: freerdp-2:2.0.0-46.rc4.el8_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: freerdp-2:2.2.0-7.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: freerdp-2:2.2.0-7.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: freerdp-2:2.2.0-7.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: freerdp-2:2.2.0-7.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: freerdp-2:2.2.0-7.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: freerdp-2:2.2.0-12.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: freerdp-2:2.2.0-12.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: freerdp-2:2.11.7-1.el9_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: freerdp-2:2.4.1-3.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: freerdp-2:2.4.1-6.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: freerdp-2:2.11.2-1.el9_4.1
View patch
ubuntupatch availablevia ubuntu_usn
Product: freerdp3 (questing)Fixed in: 3.16.0+dfsg-2ubuntu0.3
ubuntupatch availablevia ubuntu_usn
Product: freerdp3 (noble)Fixed in: 3.5.1+dfsg1-0ubuntu1.4
github_advisoryvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: freerdp

Vendor Advisories (2)

ubuntuUSN-8105-1

FreeRDP vulnerabilities

Mar 18, 2026
redhatCVE-2026-23533Important

freerdp: FreeRDP: Heap buffer overflow leads to denial of service and potential code execution

Jan 19, 2026

References

access.redhat.com / errata/RHSA-2026:2048
access.redhat.com / errata/RHSA-2026:2081
access.redhat.com / errata/RHSA-2026:2222
access.redhat.com / errata/RHSA-2026:2714
access.redhat.com / errata/RHSA-2026:2736
access.redhat.com / errata/RHSA-2026:2770
access.redhat.com / errata/RHSA-2026:2824
access.redhat.com / errata/RHSA-2026:2952
access.redhat.com / errata/RHSA-2026:3036
access.redhat.com / errata/RHSA-2026:3037
access.redhat.com / errata/RHSA-2026:3038
access.redhat.com / errata/RHSA-2026:3039
access.redhat.com / errata/RHSA-2026:3041
access.redhat.com / security/cve/CVE-2026-23533
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-23533.json
github.com / FreeRDP/FreeRDP/blob/38514dfa5813aa945a86cfbcec279033f8394468/libfreerdp/codec/clear.c
Product
github.com / FreeRDP/FreeRDP/blob/38514dfa5813aa945a86cfbcec279033f8394468/libfreerdp/codec/clear.c
Product
github.com / FreeRDP/FreeRDP/releases/tag/3.21.0
Release Notes
github.com / FreeRDP/FreeRDP/security/advisories/GHSA-32q9-m5qr-9j2v
ExploitVendor Advisory