CVE-2026-22859Critical· 9.1▾ MidnightFreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_ms…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
0.8% → 0.9%
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability is fixed in 3.20.1.
freerdp < 3.20.1Upgrade past the affected range:
freerdp 3.20.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22855Critical· 9.1FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-22858Critical· 9.1FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-24678High· 7.5FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-22853Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-91945Medium· 6.5FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays
CVE-2026-91950Medium· 6.5FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation