CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67300

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-01
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). The parser frees those nested buffers after the callback returns, so the queued async message later dispatches stale pointers, potentially causing memory corruption or a client crash.

⚡ Watch CVE-2026-67300

Get an email if CVE-2026-67300 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67300

CVE.org record

Embed the live status

CVE-2026-67300 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67300 status](https://www.csirts.com/badge/CVE-2026-67300)](https://www.csirts.com/cve/CVE-2026-67300)