Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-57156: FreeRDP: Malicious RDP peer can cause memory corruption

CVE-2026-57156 CVE-2026-57156
Summary

FreeRDP clients are affected. An attacker can exploit this vulnerability to cause memory corruption, potentially leading to crashes or other security issues. Update to version 3.28.0 or later to fix the issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
freerdp freerdp < 3.28.0
Original title
FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing
Original description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fixed in version 3.28.0.
nvd CVSS4.0 8.6
Vulnerability type
CWE-122 Heap-based Buffer Overflow
CWE-190 Integer Overflow
Published: 10 Jul 2026 · Updated: 16 Jul 2026 · First seen: 10 Jul 2026