PT-2026-61741 · Freerdp+2 · Freerdp+2

·

CVE-2026-64624

·

Published

2026-06-09

·

Updated

2026-09-04

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.28.0
Description FreeRDP treats lines starting with a forward slash in RDP files as raw command-line options, which exposes the entire CLI parser surface to untrusted files. This allows attackers to use malicious RDP files containing options such as /rdp2tcp, /cert:ignore, or /drive to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
Recommendations Update FreeRDP to version 3.28.0 or later.

Exploit

Fix

RCE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:54485
ALSA-2026:54486
ALSA-2026:54487
CVE-2026-64624
GHSA-RQ8F-9XJH-PR3M
RHSA-2026:54485
RHSA-2026:54487
RHSA-2026:58710
RHSA-2026:58712
RHSA-2026:58713
RHSA-2026:60173
RHSA-2026:61250
RHSA-2026:61251
USN-8410-1

Affected Products

Freerdp
Red Os
Rocky Linux