CVE-2026-31885: Freerdp
Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. This vulnerability is fixed in 3.24.0.
Affected products
- Freerdp Freerdp: before 3.24.0 (fixed in 3.24.0)
Published 2026-03-13. Last modified 2026-06-17.