CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67293

mediumCVSS 4.2covered by 1 sourcefirst seen 2026-08-01
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.

⚡ Watch CVE-2026-67293

Get an email if CVE-2026-67293 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67293

CVE.org record

Embed the live status

CVE-2026-67293 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67293 status](https://www.csirts.com/badge/CVE-2026-67293)](https://www.csirts.com/cve/CVE-2026-67293)