CVE-2026-31885: Freerdp

Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders due to unchecked predictor and step_index values from input data. This vulnerability is fixed in 3.24.0.

Affected products

  • Freerdp Freerdp: before 3.24.0 (fixed in 3.24.0)

Published 2026-03-13. Last modified 2026-06-17.