FreeRDP Pre-Authentication Heap Buffer Overflow Enables Remote Code Execution Against RDP Clients (CVE-2026-64620)
Scope: FreeRDP Versions 3.27.1 and Earlier (Linux, macOS, Windows, Android Clients)
Severity: Red
Published July 20, 2026, CVE-2026-64620 is a heap-based buffer overflow in FreeRDP's crypto_rsa_common() function that occurs when a modular exponentiation result is written to a fixed 32-byte heap buffer before any length check is performed, allowing a malicious RDP server to forge a ciphertext that overflows the buffer by up to 224 attacker-controlled bytes before the client has even completed authentication. Because the vulnerable code path executes before any authentication succeeds, an attacker who can position a rogue RDP server in the path of a connecting client (such as through DNS manipulation, a phishing link, or a compromised RDP bookmark) can achieve code execution on the client machine with zero prior interaction. FreeRDP is widely used across Linux desktops, macOS systems, and embedded in tools such as Remmina and GNOME Connections, making any enterprise or government environment using Linux-based RDP clients potentially at risk. Organizations must update to FreeRDP version 3.28.0 immediately, restrict RDP connections to only verified and known servers, and enforce VPN-based access for all remote desktop sessions to eliminate the possibility of rogue server interception.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.