FreeRDP released version 3.27.0 with a stronger default transport posture and several security fixes across client and server components. The update raises the default OpenSSL TLS security level to 2 and now requires a minimum of TLS 1.2, aligning remote desktop connections with stricter cryptographic standards documented by OpenSSL. The release also incorporates fixes associated with multiple GitHub Security Advisories and additional vulnerability reports from Tencent Keen Lab and another researcher.
The patched issues include validation and bounds-checking flaws in RD Gateway authentication blob handling, negotiation cookie parsing, glyph cache offset reads, and graphics header parsing. FreeRDP also fixed a server-side denial-of-service condition in the rdpsnd channel by rejecting invalid client audio formats. Alongside the security changes, the release adds Android client improvements, Azure/Entra connection stability updates, keyboard mapping changes, statistics logging APIs, and numerous fixes across channels, proxy functions, clients, and the build system.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
On 15 June 2026, FreeRDP released version 3.27.0, described as a major feature, bugfix, and cleanup release. The update raised the default TLS security level to 2, required at least TLS 1.2, and fixed multiple security issues including validation, bounds-checking, and a server-side rdpsnd denial-of-service condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.