A high-severity double-free vulnerability tracked as CVE-2026-64621 was disclosed in FreeRDP versions 3.x through 3.27.1, affecting the parsing of the selectedmonitors field in .rdp connection files. The flaw is located in freerdp_client_rdp_file_apply_to_settings() in client/common/file.c, where an error path can free a non-owning pointer and leave settings->MonitorIds dangling, leading to a second free during teardown. The issue is classified as CWE-415 and can affect FreeRDP CLI clients including xfreerdp, sdl-freerdp, and wlfreerdp in their default configurations.
Attackers could exploit the bug by persuading a user to open a crafted .rdp file containing oversized monitor tokens, resulting in a size-controlled double-free with potential impacts to integrity and availability, and limited confidentiality exposure under the published CVSS assessment. The vulnerability has been fixed in FreeRDP 3.28.0, and public references include a GitHub security advisory, a fixing commit in the FreeRDP repository, and a VulnCheck advisory.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
FreeRDP released version 3.28.0 to fix a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() affecting 3.x releases through 3.27.1. The flaw could be triggered when a victim opens a crafted .rdp file with oversized selectedmonitors tokens in default CLI clients such as xfreerdp, sdl-freerdp, and wlfreerdp.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.