C · AUGUST 2026 · CONFIRMED

FreeRDP <= 3.28.0: Critical TLS and Buffer Overflow Vulnerabilities

CVE-2026-66402Severity: CRITICAL

FreeRDP versions <= 3.28.0 have been confirmed to contain multiple critical vulnerabilities, including TLS certificate identity validation weaknesses and a heap-based buffer overflow, affecting software supply chains.

What happened

FreeRDP versions <= 3.28.0 are affected by multiple critical vulnerabilities tracked as CVE-2026-66402, CVE-2026-67289, and CVE-2026-68579. CVE-2026-66402 involves TLS certificate identity validation weaknesses that can allow an attacker to bypass server identity verification. CVE-2026-67289 is a vulnerability where FreeRDP does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field, potentially allowing header injection. CVE-2026-68579 is a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function, which can be exploited by a malicious RDP server to execute arbitrary code.

To assess your exposure, check if your software supply chain includes FreeRDP versions <= 3.28.0. If so, consider this a critical risk and take immediate action to upgrade to FreeRDP 3.29.0 or later to mitigate these vulnerabilities. Consult the primary sources for detailed technical information and remediation steps.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If freerdp is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats