CVE-2026-44422 – FreeRDP

CVSS 7.5 IMPORTANT

“A vulnerable remote desktop client can turn a trusted connection into a direct compromise path.”

FreeRDP released patches for four high-severity vulnerabilities affecting FreeRDP. CVE-2026-40033 has a CVSS score of 8.8, which is High severity. CVE-2026-44420 has a CVSS score of 8.8, which is High severity. CVE-2026-44421 has a CVSS score of 8.8, which is High severity. CVE-2026-44422 has a CVSS score of 7.5, which is High severity.

The update addresses multiple memory safety issues, including heap-based buffer overflows, double-free conditions, and use-after-free vulnerabilities. Public proof-of-concept code is available for all four vulnerabilities. Successful exploitation could allow remote code execution, with one vulnerability also creating privilege escalation risk in affected FreeRDP environments.

Key Details

Affected Product
Freerdp Freerdp
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-415
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.