<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:00:39 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:73979 — Critical: freerdp security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: freerdp, AlmaLinux:10: freerdp-devel, AlmaLinux:10: freerdp-libs, AlmaLinux:10: freerdp-server, AlmaLinux:10: libwinpr, AlmaLinux:10: libwinpr-devel&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass (CVE-2026-91949)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: freerdp, AlmaLinux:10: freerdp-devel, AlmaLinux:10: freerdp-libs, AlmaLinux:10: freerdp-server, AlmaLinux:10: libwinpr, AlmaLinux:10: libwinpr-devel&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass (CVE-2026-91949)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73979</guid>
    </item>
    <item>
      <title>EUVD-2026-371595</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371595</link>
      <description>EUVD-2026-371595</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371595</guid>
    </item>
    <item>
      <title>fkie_cve-2026-91949</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-91949</link>
      <description>&lt;p&gt;FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-91949</guid>
    </item>
    <item>
      <title>GHSA-hcpv-8ff6-4xx8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hcpv-8ff6-4xx8</link>
      <description>&lt;p&gt;FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hcpv-8ff6-4xx8</guid>
    </item>
    <item>
      <title>RHSA-2026:73979 — security update for freerdp</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:73979</link>
      <description>&lt;p&gt;security update for freerdp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for freerdp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:73979</guid>
    </item>
    <item>
      <title>RHSA-2026:74471 — Red Hat Security Advisory: freerdp security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:74471</link>
      <description>&lt;p&gt;FreeRDP: FreeRDP: Remote code execution or client crash via malicious TS Gateway freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FreeRDP: FreeRDP: Remote code execution or client crash via malicious TS Gateway freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:74471</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-91949</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91949</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: freerdp, Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:18.04:LTS: freerdp, Ubuntu:Pro:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2, Ubuntu:24.04:LTS: freerdp3, Ubuntu:Pro:24.04:LTS: freerdp2, Ubuntu:26.04:LTS: freerdp3&lt;/p&gt;
&lt;p&gt;FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: freerdp, Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:18.04:LTS: freerdp, Ubuntu:Pro:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2, Ubuntu:24.04:LTS: freerdp3, Ubuntu:Pro:24.04:LTS: freerdp2, Ubuntu:26.04:LTS: freerdp3&lt;/p&gt;
&lt;p&gt;FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91949</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3057 — FreeRDP: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3057</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3057</guid>
    </item>
  </channel>
</rss>
