FreeRDP has 61 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 42 in the last 90 days against 5 in the 90 before. The busiest recent month was September 2026 with 22. The median CVSS is 7.5 (high), with 17 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-125 (15) and CWE-122 (14).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 42 prev 5
Weakness classes
Products
- FreeRDP 61
61
Total CVEs
17
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-55194Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol66CVE-2026-63633Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol54CVE-2026-55191Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol54CVE-2026-45700Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol54CVE-2026-23884Critical· 9.8FreeRDP is a free implementation of the Remote Desktop Protocol54
FreeRDP vulnerabilities
CVEs affecting FreeRDP, newest first. Open any entry for full detail, references, and exploit status.
61 CVEsRSS