CVE-2026-33982: Freerdp

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before the allocation, in winpr_aligned_offset_recalloc(). This issue has been patched in version 3.24.2.

Affected products

  • Freerdp Freerdp: before 3.24.2 (fixed in 3.24.2)

Published 2026-03-30. Last modified 2026-06-17.