A critical heap-based buffer overflow tracked as CVE-2026-68579 affects FreeRDP versions up to and including 3.29.0 in the Windows clipboard client function CliprdrStream_Read. The flaw occurs because FreeRDP copies server-returned file contents using an attacker-controlled length value rather than the fixed-size buffer length supplied by the caller, creating an out-of-bounds heap write. The issue has been rated CVSS 9.6 under v3.1 and 8.7 under v4.0.
A malicious or compromised RDP server can trigger the bug during clipboard file paste operations by sending an oversized CB_FILECONTENTS_RESPONSE, causing attacker-controlled data to be written into the heap buffer of the paste consumer, such as explorer.exe. The vulnerable code is located in client/Windows/wf_cliprdr.c, and the reported fix is to upgrade to FreeRDP 3.30.0 or later.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 2, 2026, VulnCheck and downstream CVE reporting published details for CVE-2026-68579, describing the FreeRDP CliprdrStream_Read heap overflow as remotely exploitable and recommending upgrades to version 3.30.0 or later. The issue was rated Critical under CVSS v3.1 with a score of 9.6.
FreeRDP version 3.30.0 fixed a heap-based buffer overflow in the Windows clipboard client function CliprdrStream_Read that affected versions up to and including 3.29.0. The flaw allowed a malicious or compromised RDP server to trigger an out-of-bounds heap write during clipboard file paste operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.