CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68580

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-02
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

⚡ Watch CVE-2026-68580

Get an email if CVE-2026-68580 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-68580

CVE.org record

Embed the live status

CVE-2026-68580 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68580 status](https://www.csirts.com/badge/CVE-2026-68580)](https://www.csirts.com/cve/CVE-2026-68580)