[UPDATE] [hoch] FreeRDP: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen,um nicht näher spezifizierte Auswirkungen zu verursachen, potenziell beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.
CSIRTS triage
- What
- Multiple unspecified vulnerabilities in FreeRDP enabling arbitrary code execution, security bypass, data manipulation, information disclosure, and denial of service.
- Who is affected
- FreeRDP users and systems using affected versions for remote desktop protocol operations.
- Urgency
- High priority; arbitrary code execution and multiple impact vectors warrant immediate patching.
- Action
- Update FreeRDP to patched versions addressing CVE-2026-55191, CVE-2026-55192, CVE-2026-55193, CVE-2026-55194, CVE-2026-55564, and CVE-2026-55648.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreeRDP
Get an email when a new FreeRDP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1933
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-551910.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-551920.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-551930.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-551940.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-555640.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-556480.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55191 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55192 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55193 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55194 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55564 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55648 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-55648: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_imag…nvd
- mediumCVE-2026-55564: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_ca…nvd
- unknownCVE-2026-55194: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_r…nvd
- unknownCVE-2026-55193: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clie…nvd
- unknownCVE-2026-55192: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.26…nvd
- unknownCVE-2026-55191: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clie…nvd
Recent advisories for FreeRDP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [hoch] FreeRDP: Mehrere Schwachstellencert-bund · 2026-09-10
- medium[UPDATE] [mittel] FreeRDP: Mehrere Schwachstellencert-bund · 2026-09-04
- mediumCVE-2026-85090: FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1…nvd · 2026-09-03
- mediumCVE-2026-85089: FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Sa…nvd · 2026-09-03
- medium[NEW] [medium] FreeRDP: Multiple vulnerabilities enable unspecified attackcert-bund · 2026-09-03
- high[NEW] [high] FreeRDP: Vulnerability allows code executioncert-bund · 2026-09-02
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11