Our takeCERT-Bund reports a code-execution flaw in FreeRDP that a remote unauthenticated attacker can exploit. Update if you run it yourself.Cyber Resilience desk
Sources (1)
- cert_bund · cert_bund
What this means for you — Security leader:CERT-Bund confirmed a remote code-execution flaw in FreeRDP that an unauthenticated attacker can trigger. Update to a fixed version if you self-host FreeRDP or use it in any client or server role.
What this means for you — Lean IT orgs:FreeRDP has a confirmed remote code-execution flaw. Update it now if you run the software yourself; most lean teams using only the built-in Windows RDP client are unaffected.
What this means for you — MSP:CERT-Bund confirmed a remote code-execution vulnerability in FreeRDP. Check every client and server deployment across your customer base and apply the update immediately where present.
What this means for you — Researcher:CERT-Bund advisory WID-SEC-2026-2413 flags a confirmed remote code-execution vulnerability in FreeRDP. Review the details if you maintain or fuzz RDP-related code.