Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23883

30
FAUCET Score

CVE-2026-23883 is a critical use-after-free vulnerability in FreeRDP versions prior to 3.21.0, affecting the Remote Desktop Protocol implementation. A malicious server can trigger this flaw, leading to a client-side crash (Denial of Service) and potentially heap corruption with a risk of arbitrary code execution. This vulnerability has a CVSS score of 9.8 (Critical) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and concern.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.21.0CPE matchmatch criteria
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 10th percentile among its peer group of 36,897 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: freerdp-2:2.11.7-1.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: freerdp-2:3.10.3-5.el10_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: freerdp-2:3.10.3-3.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: freerdp-2:2.11.7-2.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: freerdp-2:2.11.7-1.el9_7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: freerdp-2:2.4.1-3.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: freerdp-2:2.4.1-6.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: freerdp-2:2.11.2-1.el9_4.1
View patch
ubuntupatch availablevia ubuntu_usn
Product: freerdp3 (questing)Fixed in: 3.16.0+dfsg-2ubuntu0.3
ubuntupatch availablevia ubuntu_usn
Product: freerdp3 (noble)Fixed in: 3.5.1+dfsg1-0ubuntu1.4
github_advisoryvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: freerdp

Vendor Advisories (2)

ubuntuUSN-8105-1

FreeRDP vulnerabilities

Mar 18, 2026
redhatCVE-2026-23883Important

freerdp: FreeRDP: Arbitrary code execution and denial of service via malicious server

Jan 19, 2026

References

access.redhat.com / errata/RHSA-2026:2048
access.redhat.com / errata/RHSA-2026:2081
access.redhat.com / errata/RHSA-2026:2222
access.redhat.com / errata/RHSA-2026:2736
access.redhat.com / errata/RHSA-2026:2770
access.redhat.com / errata/RHSA-2026:2824
access.redhat.com / errata/RHSA-2026:2952
access.redhat.com / errata/RHSA-2026:3037
access.redhat.com / security/cve/CVE-2026-23883
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-23883.json
github.com / FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/client/X11/xf_graphics.c
Product
github.com / FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/client/X11/xf_graphics.c
Product
github.com / FreeRDP/FreeRDP/blob/3370e30e92a021eb680892dda14d642bc8b8727c/libfreerdp/cache/pointer.c
Product
github.com / FreeRDP/FreeRDP/releases/tag/3.21.0
Release Notes
github.com / FreeRDP/FreeRDP/security/advisories/GHSA-qcrr-85qx-4p6x
ExploitVendor Advisory