CVE-2026-24678High· 7.5▾ TwilightFreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. Thi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
0.6% → 0.7%
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0.
freerdp < 3.22.0Upgrade past the affected range:
freerdp 3.22.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22859Critical· 9.1FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-22858Critical· 9.1FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-22855Critical· 9.1FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-22853Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-91957Low· 3.1FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration
CVE-2026-44422High· 7.5FreeRDP is a free implementation of the Remote Desktop Protocol