FreeRDP 3.31.0 fixes 22 security vulnerabilities, including a three-flaw chain that can yield pre-authentication remote code execution against GNOME Remote Desktop (GRD) Remote Login deployments. The demonstrated chain bypasses system-wide remote-login authentication, uses an RDPGFX ResetGraphics message to disclose uninitialized heap memory, and triggers an out-of-bounds write during RDPDR device-redirection channel processing to control an indirect function call.
The resulting shell runs under a temporary gdm-greeter-N account rather than root, but testing found that account was not sandboxed on affected Fedora and Ubuntu configurations. The complete exploit path has limited exposure because it requires GRD 51 or later with RDPDR enabled; however, organizations should update FreeRDP and embedded distributions to 3.31.0 promptly. The release also remediates issues across graphics decoding, dynamic virtual channels, RD Gateway parsing, clipboard, smart-card, USB/device redirection, memory management, and authentication/error-handling components.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important-severity advisory RHSA-2026:65855 for RHEL 8 and RHEL AUS 8.4, updating FreeRDP packages to remediate CVE-2026-55194, CVE-2026-67288, CVE-2026-67291, and CVE-2026-67301. The advisory addresses a potentially arbitrary-code-execution heap overflow, denial-of-service flaws, and a memory-disclosure or denial-of-service issue; Nessus reports exploits are available.
TencentOS published TSSA-2026:0966 for FreeRDP on TencentOS Server 4, addressing CVE-2026-55191, CVE-2026-55193, and CVE-2026-55194. The associated Nessus check reports no known exploits and indicates exploitation requires user interaction.
Rocky Linux published advisory RLSA-2026:62571 for Rocky Linux 8, updating FreeRDP-related packages to address four flaws, including CVE-2026-55194, a heap-buffer overflow that can permit arbitrary code execution through a crafted RPC response.
Red Hat published RHSA-2026:62571 for RHEL 8 and RHEL EUS 8.10, rated Important, addressing four FreeRDP flaws: CVE-2026-55194, CVE-2026-67288, CVE-2026-67291, and CVE-2026-67301. The update fixes a potentially code-execution-capable Gateway RPC heap overflow as well as denial-of-service and memory-disclosure issues.
AlmaLinux published ALSA-2026:61378 for FreeRDP and WinPR packages in AlmaLinux 10 repositories, addressing 12 vulnerabilities including CVE-2026-55194, CVE-2026-67288, CVE-2026-67291, CVE-2026-67301, CVE-2026-63633, and CVE-2026-67304. Nessus metadata for the advisory indicates exploits are available.
Fedora published security advisory FEDORA-2026-e0f5d28f57 for the FreeRDP package on Fedora 43. The supplied record does not specify CVEs, affected or fixed versions, severity, or vulnerability details, and states no known exploits are available.
Unity Linux published security update UTSA-2026-035839 to address CVE-2026-23948, a remotely exploitable, no-authentication denial-of-service vulnerability rated CVSS 7.5. The patch was published on July 10, 2026; the referenced security-check information reported no known exploits.
Unity Linux published UTSA-2026-106772 for Unity Linux 20.1050a, 20.1060a, and 20.1070a to address CVE-2026-67291, a FreeRDP glyph-fragment heap out-of-bounds read that a malicious RDP server can use to crash the client. The update remediates affected FreeRDP versions 3.28.0 and earlier; the advisory states exploits are available.
FreeRDP versions before 3.29.0 contain a null-pointer dereference in smartcard cache request decoding when smartcard emulation is enabled. Crafted SCARD_IOCTL_READCACHEA or SCARD_IOCTL_WRITECACHEA requests with a NULL LookupName pointer cause strlen() to terminate the client process; Red Hat addressed the flaw in RHEL 9 and 10 through RHSA-2026:61379 and RHSA-2026:61378.
Researchers disclosed a chain of three FreeRDP flaws that can bypass GNOME Remote Desktop Remote Login authentication, leak heap memory to aid ASLR bypass, and corrupt an indirect callback through an RDPDR out-of-bounds write. The demonstrated code execution runs as a temporary gdm-greeter-N account; the complete chain requires GRD 51+ with RDPDR enabled and was described as limited to certain Fedora, CentOS Stream, and Arch Linux deployments.
FreeRDP released version 3.31.0, remediating 22 GitHub Security Advisories and additional bugs across graphics decoding, virtual channels, gateway parsing, clipboard, smart-card, USB, device-redirection, and memory-management components. The release fixes all three vulnerabilities used in the demonstrated GNOME Remote Desktop attack chain, and maintainers urged users and distributors to update promptly.
FreeRDP disclosed that versions before 3.27.0 mishandle TS Gateway RPC response reassembly by allocating based on a server-controlled alloc_hint rather than incoming StubLength. A crafted PTYPE_RESPONSE can write attacker-controlled data beyond a 4096-byte buffer, potentially causing a crash or heap-corruption-based code execution; FreeRDP 3.27.0 fixes the issue and Red Hat addressed it in RHEL 9 and 10 advisories RHSA-2026:61379 and RHSA-2026:61378.
FreeRDP versions 3.28.0 and earlier were found vulnerable to a heap out-of-bounds read in glyph-cache processing of server-controlled GLYPH_FRAGMENT_ADD updates. A malicious RDP server can send an oversized fragment-size declaration to crash the FreeRDP client; the issue is fixed in FreeRDP 3.29.0 and was addressed for RHEL 9 and 10 through RHSA-2026:61379 and RHSA-2026:61378.
Red Hat addressed CVE-2026-67301 in Red Hat Enterprise Linux 9 and 10 through RHSA-2026:61379 and RHSA-2026:61378. The flaw affects FreeRDP versions before 3.29.0 and allows a malicious RDP server to trigger client memory disclosure or a crash through crafted asynchronous PolygonSC or PolygonCB update orders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
15 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.