8.8

CVSS3.1

CVE-2026-26965 - FreeRDP has Out-of-bounds Write

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXDst) + nChannel` without verifying that `(nYDst+nSrcHeight)` fits in the destination heig…

📅 Published: Feb. 25, 2026, 8:59 p.m. 🔄 Last Modified: Feb. 25, 2026, 8:59 p.m.

8.1

CVSS3.1

CVE-2026-3172 - pgvector buffer overflow in parallel HNSW index build

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

📅 Published: Feb. 25, 2026, 8:59 p.m. 🔄 Last Modified: Feb. 25, 2026, 8:59 p.m.

8.8

CVSS3.1

CVE-2026-26955 - FreeRDP has Out-of-bounds Write

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination …

📅 Published: Feb. 25, 2026, 8:47 p.m. 🔄 Last Modified: Feb. 25, 2026, 8:47 p.m.

5

CVSS4.0

CVE-2026-27015 - FreeRDP: Smartcard NDR Alignment Padding Triggers Reachable WINPR_ASSERT Abort (Client DoS)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. T…

📅 Published: Feb. 25, 2026, 8:44 p.m. 🔄 Last Modified: Feb. 25, 2026, 8:44 p.m.

5.5

CVSS4.0

CVE-2026-26271 - Buffer Overread in FreeRDP Icon Processing

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network when a client proces…

📅 Published: Feb. 25, 2026, 8:40 p.m. 🔄 Last Modified: Feb. 25, 2026, 8:40 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here