FreeRDP is a widely deployed open-source Remote Desktop Protocol client and library embedded across numerous third-party applications, virtualization platforms, and enterprise remote-access solutions, making its security posture relevant far beyond its direct user base. The vendor's vulnerabilities skew strongly toward critical-severity outcomes and concentrate in memory-safety weakness classes—out-of-bounds reads and writes, use-after-free conditions, heap-based buffer overflows, and integer overflows—that are typical of C-based protocol parsers handling untrusted network input. These flaws recur across the RDP parsing and rendering pipeline and carry particular risk because they affect systems handling authentication and screen-sharing traffic in environments where remote access is a routine operational dependency. Defenders should treat FreeRDP updates as high-priority, especially for internet-reachable systems and virtualization hosts, and inventory downstream products that bundle the library. Live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freerdp over time
Signals from CVEs in this vendor scope (180 CVEs).
180 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-64620CRITICAL FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation | Jul 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-57156CRITICAL FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfre | Jul 10, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-45700CRITICAL FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In | May 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-44420HIGH FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard | May 29, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-44421HIGH FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending c | May 29, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-40033HIGH FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs | May 26, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-23533CRITICAL FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when malici | Jan 19, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-57158CRITICAL FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in p | Jul 10, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-55827HIGH FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and heig | Jul 10, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-56297HIGH FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malic | Jul 8, 2026 | 8.1 | 36 | NO | NO |
Signals from CVEs in this vendor scope (180 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freerdp.
Media articles that mention a CVE ID that affects a product developed by Freerdp — matched by CVE ID, not by vendor name.