Red Hat released Important security updates for freerdp across multiple Red Hat Enterprise Linux product streams, including RHEL 8, 9, and 10, SAP Solutions channels, Extended Update Support, and related builder repositories. The advisories address four prominently tracked vulnerabilities: CVE-2026-64624, which allows arbitrary code execution through malicious .rdp files parsed as raw command-line options; CVE-2026-67299, a client-side heap use-after-free in asynchronous WINDOW_ICON_ORDER handling that can crash a client; CVE-2026-67289, which lets a malicious RDP server inject arbitrary headers or requests into an HTTP proxy CONNECT request via a crafted redirection target; and CVE-2026-68580, an integer overflow in audio input redirection that can cause remote code execution or denial of service.
Updated packages were published in several streams, including 2.11.7-11.el8_10 for RHEL 8, 2.11.7-7.el9_8.5, 2.11.7-1.el9_6.12, 2.11.2-1.el9_4.10, and 2.4.1-6.el9_2.11 for RHEL 9 variants, and 3.10.3-12.el10_2.8 and 3.10.3-3.el10_0.11 for RHEL 10 channels. Red Hat said the flaws can be triggered by malicious or compromised RDP servers, crafted redirection data, or specially prepared RDP files, with impacts ranging from client crashes and proxy abuse to heap corruption and code execution on affected systems.

See affected versions and whether adversaries are exploiting it.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat published the Important-rated RHSA-2026:62401 security update for Red Hat Enterprise Linux 7, updating affected FreeRDP packages to fix CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:61250 for RHEL 8, providing security updates for freerdp, freerdp-libs, libwinpr, and libwinpr-devel. The Important-rated advisory remediates CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:61251 for Red Hat Enterprise Linux 8, providing FreeRDP package security updates for CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580. Red Hat classified the advisory as Important.
Red Hat published RHSA-2026:60173 for RHEL 8, including RHEL AUS 8.4 configurations, updating FreeRDP packages to remediate CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:58713 for Red Hat Enterprise Linux 9.6 Extended Update Support, releasing freerdp 2.11.7-1.el9_6.12 packages. The update fixes CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:58712 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related offerings, releasing freerdp 2.4.1-6.el9_2.11 packages. The advisory fixes CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:58710 for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related channels, releasing freerdp 2.11.2-1.el9_4.10. The update addresses CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:58711 for Red Hat Enterprise Linux 10.0 Extended Update Support, releasing FreeRDP 3.10.3-3.el10_0.11 packages. The update fixes CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580, plus two additional FreeRDP flaws.
TencentOS published security update TSSA-2026:0918 for FreeRDP on TencentOS Server 3, addressing CVE-2026-64624, CVE-2026-67289, CVE-2026-67299, and CVE-2026-68580. The update's referenced patch publication date was August 13, 2026.
Red Hat published Bugzilla entry 2502766 for CVE-2026-64621, a double-free vulnerability in FreeRDP before 3.28.0 triggered by parsing the selectedmonitors field in a crafted .rdp file. The issue can affect CLI clients including xfreerdp, sdl-freerdp, and wlfreerdp, and Red Hat states it was addressed in RHEL 10 and RHEL 10.0 EUS advisories.
Red Hat published Bugzilla entry 2502752 for CVE-2026-64620, a FreeRDP heap-based buffer overflow in crypto_rsa_common() that can lead to remote code execution or denial of service. The issue affects FreeRDP versions before 3.28.0 and was fixed upstream in FreeRDP 3.28.0.
Red Hat published Bugzilla entries documenting CVE-2026-67299, a FreeRDP denial-of-service flaw via crafted WindowIcon async messages, and CVE-2026-67289, an HTTP proxy request injection issue via redirection. Both entries state the issues were fixed in FreeRDP 3.29.0 and across multiple RHEL streams.
Red Hat published RHSA-2026:54486 for Red Hat Enterprise Linux 10, releasing FreeRDP 3.10.3-12.el10_2.8 packages. The advisory fixes CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580, along with two additional FreeRDP vulnerabilities.
Red Hat published RHSA-2026:54487 for Red Hat Enterprise Linux 9, releasing FreeRDP 2.11.7-7.el9_8.5 packages that address CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat published RHSA-2026:54485 for Red Hat Enterprise Linux 8, shipping updated FreeRDP packages to fix CVE-2026-64624, CVE-2026-67299, CVE-2026-67289, and CVE-2026-68580.
Red Hat reported Bugzilla entry 2510125 for CVE-2026-68580, a high-severity FreeRDP flaw involving integer overflow in the audio input redirection channel that can lead to remote code execution or denial of service.
Red Hat reported Bugzilla entry 2503096 for CVE-2026-64624, an arbitrary code execution issue in FreeRDP caused by unsafe handling of malicious RDP files.
Unity Linux published advisory UTSA-2026-104838 for affected Unity Linux 20 systems, updating FreeRDP to remediate CVE-2026-67289. The vulnerability permits a malicious RDP server to inject arbitrary headers or requests into an HTTP proxy CONNECT request through control characters in a redirection TargetNetAddress field.
Unity Linux advisory UTSA-2026-104830 updated FreeRDP on Unity Linux 20.1050a, 20.1060a, and 20.1070a to address CVE-2026-68580. The flaw is an integer overflow in audio input redirection handling that a malicious RDP server can exploit to cause a heap buffer overflow on ALSA or denial of service across affected backends.
Unity Linux published advisory UTSA-2026-104834 for Unity Linux 20.1050a, 20.1060a, and 20.1070a systems, updating FreeRDP to address CVE-2026-67299. The flaw is a client-side heap use-after-free in asynchronous WINDOW_ICON_ORDER handling that a malicious RDP server can trigger to cause memory corruption and a client crash.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
22 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.