CVE-2026-40033High· 8.8▾ TwilightFreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
0.8% → 1.0%
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
freerdp < 3.26.0Upgrade past the affected range:
freerdp 3.26.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44421High· 8.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-45700Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-44420High· 8.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-23534Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-23533Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-23532Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol