<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:14:01.992715+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:73979</id>
    <title>ALSA-2026:73979 — Critical: freerdp security update</title>
    <updated>2026-10-02T15:14:02.083557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: freerdp, AlmaLinux:10: freerdp-devel, AlmaLinux:10: freerdp-libs, AlmaLinux:10: freerdp-server, AlmaLinux:10: libwinpr, AlmaLinux:10: libwinpr-devel</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.</p>
<p>Security Fix(es):</p>
<p>* freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass (CVE-2026-91949)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:73979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371595</id>
    <title>EUVD-2026-371595</title>
    <updated>2026-10-02T15:14:02.083622+00:00</updated>
    <content>EUVD-2026-371595</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371595"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-91949</id>
    <title>fkie_cve-2026-91949</title>
    <updated>2026-10-02T15:14:02.083639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-91949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hcpv-8ff6-4xx8</id>
    <title>GHSA-hcpv-8ff6-4xx8</title>
    <updated>2026-10-02T15:14:02.083664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hcpv-8ff6-4xx8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73979</id>
    <title>RHSA-2026:73979 — Red Hat Security Advisory: freerdp security update</title>
    <updated>2026-10-02T15:14:02.083680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:74471</id>
    <title>RHSA-2026:74471 — Red Hat Security Advisory: freerdp security update</title>
    <updated>2026-10-02T15:14:02.083698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP: FreeRDP: Remote code execution or client crash via malicious TS Gateway freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:74471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91949</id>
    <title>UBUNTU-CVE-2026-91949</title>
    <updated>2026-10-02T15:14:02.083715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: freerdp, Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:18.04:LTS: freerdp, Ubuntu:Pro:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2, Ubuntu:24.04:LTS: freerdp3, Ubuntu:Pro:24.04:LTS: freerdp2, Ubuntu:26.04:LTS: freerdp3</p>
<p>FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91949"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3057</id>
    <title>WID-SEC-W-2026-3057 — FreeRDP: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T15:14:02.083745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3057"/>
  </entry>
</feed>
