CVE-2026-33982: Freerdp
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.
Affected products
- Freerdp Freerdp: before 3.24.2 (fixed in 3.24.2)
Published 2026-03-30. Last modified 2026-06-17.