CVE-2026-91958: Freerdp
Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
Affected products
- Freerdp Freerdp: from 3.11.0, before 3.31.0 (fixed in 3.31.0)
Published 2026-09-15. Last modified 2026-09-24.