THREAT OPS › Threat News › FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated
FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated
<p>Posted by Samuel Page on Sep 01</p>FreeRDP 3.31.0 (2026-08-26) fixes 5 vulnerabilities in FreeRDP's server role<br /> that Bynario reported, as well as 17 other security issues. We were able to<br /> demonstrate that 3 of the issues could be chained to achieve pre-auth remote<br /> code execution, however we believe exposure to this specific chain is limited<br /> (more detail below).<br /
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Original source: https://seclists.org/oss-sec/2026/q3/633